First published: Wed Mar 30 2022(Updated: )
Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
Credit: Leecraso 360 Vulnerability Research InstituteGuang Gong 360 Vulnerability Research Institute chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <100.0.4896.88 | 100.0.4896.88 |
Google Chrome (Trace Event) | <100.0.4896.88 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-1312 has a high severity level as it allows a potential sandbox escape through a malicious Chrome Extension.
To fix CVE-2022-1312, users should update Google Chrome to version 100.0.4896.88 or later.
CVE-2022-1312 involves a use-after-free vulnerability which can be exploited through malicious Chrome Extensions.
Google Chrome versions prior to 100.0.4896.88 are affected by CVE-2022-1312.
The potential impact of CVE-2022-1312 includes unauthorized access or execution of arbitrary code due to sandbox escape.