CVE-2022-1311: Use after free in Chrome OS shell
Published Mar 28, 2022
·Updated
Use after free in shell in Google Chrome on ChromeOS prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Nan Wang@@eternalsakura13(360 Alpha Lab), Guang Gong(360 Alpha Lab)
Affected Software
3 affected componentsFixes available
Google Chrome<100.0.4896.88
100.0.4896.88
Google Chrome<100.0.4896.88
Google Chrome OS
Remediation
Patch Available
Event History
Mar 28, 2022
CVE Published
12:00 AM
Jul 25, 2022
CVE Published
via MITRE·01:40 PM
Data Sourced
via MITRE·01:40 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is CVE-2022-1311?
CVE-2022-1311 is a vulnerability in Google Chrome on ChromeOS that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
2
What is the severity of CVE-2022-1311?
CVE-2022-1311 has a severity rating of 8.8, which is classified as high.
3
How does CVE-2022-1311 affect Google Chrome and ChromeOS?
CVE-2022-1311 affects Google Chrome on ChromeOS prior to version 100.0.4896.88.
4
How can a remote attacker exploit CVE-2022-1311?
A remote attacker can potentially exploit CVE-2022-1311 by using a crafted HTML page to trigger a use-after-free vulnerability in the shell of Google Chrome.
5
Is Google Chrome OS vulnerable to CVE-2022-1311?
No, Google Chrome OS is not vulnerable to CVE-2022-1311.