ZeroHour

CVE-2022-3075

KEVmass

Actively Exploited Sandbox Escape via Insufficient Mojo Validation in Google Chrome

CISA: Google Chromium Mojo Insufficient Data Validation Vulnerability

CVSS 3.1
9.6 critical
EPSS
6%p93
Published
()
KEV added
AI analysis

CVE-2022-3075 is an insufficient data validation flaw (CWE-20) in Mojo, the inter-process communication layer of the Chromium browser engine, affecting Google Chrome versions prior to 105.0.5195.102. An attacker triggers it via a crafted HTML page after first compromising the browser's renderer process; the bug then allows code to escape the Chrome sandbox. Successful exploitation yields execution outside the renderer sandbox, potentially giving the attacker broader access to the host, which the 9.6 CVSS score reflects via network attack vector, user interaction, and high impact across the changed scope. All users of Google Chrome prior to 105.0.5195.102 are exposed, and Fedora, which ships Chromium-based browser packages, is also listed as affected. The flaw was confirmed as a zero-day exploited in the wild — Google's ninth actively exploited Chrome zero-day of 2022 — was added to CISA's KEV catalog on 2022-09-08, and carries a 5.8% EPSS probability of exploitation within 30 days.

What to do: Update Google Chrome to 105.0.5195.102 or later on all desktop platforms and restart the browser; verify the running version via chrome://version. Fedora users should immediately apply system updates to receive rebuilt Chromium packages. Because this flaw is in CISA's Known Exploited Vulnerabilities catalog, KEV-bound organizations (including federal agencies) must apply the vendor updates by the required deadline.

Affected
Google Chromeall versions prior to 105.0.5195.102
Fedora Project Fedora (Chromium-based browser packages)Chromium code prior to 105.0.5195.102; exact Fedora package versions not specified in the data
Estimated exposure
mass≈3 billion+ users (order of magnitude: billions, based on Chrome's dominant market share) — Chrome holds roughly two-thirds of global browser market share with an estimated 3+ billion users, and Fedora additionally distributes Chromium packages to its multi-million-user installed base, so exposure is plausibly in the billions…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium Mojo
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlefedoraproject
Products
chrome, fedora
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news