CVE-2022-2478: Use after free in PDF
Published Jun 13, 2022
·Updated
Use after free in PDF in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
triplepwns
Affected Software
2 affected componentsFixes available
Google Chrome<103.0.5060.134
103.0.5060.134
Google Chrome<103.0.5060.134
Event History
Jun 13, 2022
CVE Published
12:00 AM
Jul 28, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-2478?
CVE-2022-2478 is classified as a high-severity vulnerability that could potentially lead to heap corruption.
2
How do I fix CVE-2022-2478?
To fix CVE-2022-2478, update Google Chrome to version 103.0.5060.134 or later.
3
What type of vulnerability is CVE-2022-2478?
CVE-2022-2478 is a use-after-free vulnerability found in the PDF rendering component of Google Chrome.
4
Can CVE-2022-2478 be exploited remotely?
Yes, CVE-2022-2478 can be exploited remotely via a specially crafted HTML page.
5
Which versions of Google Chrome are affected by CVE-2022-2478?
Google Chrome versions prior to 103.0.5060.134 are affected by CVE-2022-2478.