CVE-2022-2156: Use after free in Base
Use after free in Core in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-2156?
The severity of CVE-2022-2156 is high with a score of 8.8.
How does CVE-2022-2156 affect Google Chrome?
CVE-2022-2156 affects Google Chrome versions prior to 103.0.5060.53.
How does CVE-2022-2156 affect Fedora?
CVE-2022-2156 affects Fedora versions 35 and 36.
How can a remote attacker potentially exploit CVE-2022-2156?
A remote attacker can potentially exploit CVE-2022-2156 by using a crafted HTML page to exploit heap corruption.
Where can I find more information about CVE-2022-2156?
More information about CVE-2022-2156 can be found at the following references: <ul></li><li>[Google Chrome Releases](https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html)</li><li>[Chromium Bug Tracker](https://crbug.com/1335458)</li><li>[Fedora Project Mailing List](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5BQRTR4SIUNIHLLPWTGYSDNQK7DYCRSB/)</li></ul>