CVE-2022-2853: Heap buffer overflow in Downloads
Published Aug 4, 2022
·Updated
Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Credit
Sergei Glazunov(Google Project Zero)
Affected Software
6 affected componentsFixes available
Google Chrome<104.0.5112.101
104.0.5112.101
Google Chrome<104.0.5112.101
Google Android
fedoraproject fedora=37
All of the following
Google Chrome<104.0.5112.101
Google Android
Remediation
Event History
Aug 4, 2022
CVE Published
12:00 AM
Sep 26, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-2853?
CVE-2022-2853 has a severity rating that indicates a heap buffer overflow could lead to potential exploitation by remote attackers.
2
How do I fix CVE-2022-2853?
To fix CVE-2022-2853, you should update Google Chrome to version 104.0.5112.101 or later.
3
What systems are affected by CVE-2022-2853?
CVE-2022-2853 affects Google Chrome for Android prior to version 104.0.5112.101.
4
What type of vulnerability is CVE-2022-2853?
CVE-2022-2853 is classified as a heap buffer overflow vulnerability.
5
Can CVE-2022-2853 be exploited remotely?
Yes, CVE-2022-2853 can potentially be exploited by a remote attacker if the renderer process is compromised.