CVE-2022-3038highunder attackCWE-416

CVE-2022-3038: high-severity vulnerability in Google Chrome

Published · Updated

76Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 25%
from disclosure to weapon
Published on NVDSep 26
CISA KEV+185d
exploitation probability
25%top 2% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
Action required by CISAfederal deadline: 2023-04-20

Apply updates per vendor instructions.

In short

Google Chrome had a flaw where freed memory could be used again, allowing attackers to corrupt data on your computer through a malicious webpage.

Technical detail

Use-after-free vulnerability in Chrome's Network Service prior to version 105.0.5195.52 enables heap corruption exploitation via crafted HTML. Remote attack vector requires user interaction (visiting malicious page); impact includes potential code execution or information disclosure through heap memory manipulation.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Google · Chrome
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.