CVE-2022-0306
25Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 85%
exploitation probability
85%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
In short
A memory error in PDFium (PDF viewer in Chrome) allows attackers to crash your browser or potentially execute malicious code by tricking you into viewing a specially crafted webpage.
Technical detail
Heap buffer overflow in PDFium's PDF parsing module affects Chrome versions before 97.0.4692.99. Remote attack vector via crafted HTML/PDF content; no user privileges required. Potential for arbitrary code execution or denial of service through heap memory corruption.
Summary generated and translated by AI from the official description.
Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected products
Google · Chrome