CVE-2022-3038: high-severity vulnerability in Google Chrome
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
Google Chrome had a flaw where freed memory could be used again, allowing attackers to corrupt data on your computer through a malicious webpage.
Use-after-free vulnerability in Chrome's Network Service prior to version 105.0.5195.52 enables heap corruption exploitation via crafted HTML. Remote attack vector requires user interaction (visiting malicious page); impact includes potential code execution or information disclosure through heap memory manipulation.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.