CVE-2022-3038
KEV PoC massUse-After-Free in Chromium Network Service Affects Chrome, Edge, Opera
CISA: Google Chromium Network Service Use-After-Free Vulnerability
Google Chromium's Network Service contains a use-after-free vulnerability (CWE-416) that a remote attacker can trigger via a crafted HTML page, potentially causing heap corruption in the browser process. An attacker who successfully exploits the flaw could achieve memory corruption that may lead to browser crashes or arbitrary code execution when a user visits attacker-controlled web content. Any application built on Chromium is potentially affected, including but not limited to Google Chrome, Microsoft Edge, and Opera, meaning the impact spans a very large share of the world's browser users. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2023-03-30, indicating confirmed exploitation in the wild, though ransomware association is unknown and no public proof-of-concept is cataloged. No CVSS score is available yet, but EPSS assigns a 24.7% probability of exploitation within 30 days (98th percentile), underscoring elevated exploitation risk.
What to do: Apply browser updates per vendor instructions immediately — update Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers deployed in your environment to the latest vendor-supplied patched releases (exact fixed version numbers were not provided in this data; check each vendor's security advisory). Because the flaw is confirmed exploited in the wild and listed in CISA KEV, prioritize patching internet-facing browsing endpoints and users who routinely visit untrusted web content; there are no reliable workarounds beyond patching, though limiting browsing to trusted sites reduces exposure.
| Google Chromium Network Service | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- Affected
- Google Chromium Network Service
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- googlefedoraproject
- Products
- chrome, fedora
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H