CVE-2022-0306: Heap buffer overflow in PDFium
Published Dec 29, 2021
·Updated
Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Sergei Glazunov(Google Project Zero)
Affected Software
2 affected componentsFixes available
Google Chrome<97.0.4692.99
97.0.4692.99
Google Chrome<97.0.4692.99
Event History
Dec 29, 2021
CVE Published
12:00 AM
Feb 12, 2022
CVE Published
via MITRE·01:35 AM
Data Sourced
via MITRE·01:35 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-0306?
CVE-2022-0306 is considered a high severity vulnerability as it allows remote attackers to exploit heap corruption.
2
How do I fix CVE-2022-0306?
To fix CVE-2022-0306, users should update Google Chrome to version 97.0.4692.99 or later.
3
Which versions of Google Chrome are affected by CVE-2022-0306?
CVE-2022-0306 affects all versions of Google Chrome prior to 97.0.4692.99.
4
What could an attacker achieve by exploiting CVE-2022-0306?
An attacker could potentially execute arbitrary code or crash the browser by exploiting CVE-2022-0306.
5
Is there a workaround for CVE-2022-0306?
There is no specific workaround for CVE-2022-0306; updating to the latest version is the recommended action.