CVE-2022-2858: Use after free in Sign-In Flow
Published Jul 5, 2022
·Updated
Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction.
Credit
raven at KunLun lab
Affected Software
3 affected componentsFixes available
Google Chrome<104.0.5112.101
104.0.5112.101
Google Chrome<104.0.5112.101
fedoraproject fedora=37
Remediation
Event History
Jul 5, 2022
CVE Published
12:00 AM
Sep 26, 2022
CVE Published
via MITRE·03:01 PM
Data Sourced
via MITRE·03:01 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-2858?
CVE-2022-2858 has a medium severity rating due to its potential to cause heap corruption.
2
How do I fix CVE-2022-2858?
To fix CVE-2022-2858, users should upgrade Google Chrome to version 104.0.5112.101 or newer.
3
What versions of Google Chrome are affected by CVE-2022-2858?
CVE-2022-2858 affects Google Chrome versions prior to 104.0.5112.101.
4
Can CVE-2022-2858 be exploited remotely?
Yes, CVE-2022-2858 can potentially be exploited by a remote attacker through specific UI interaction.
5
What platforms are impacted by CVE-2022-2858?
CVE-2022-2858 impacts Google Chrome on all platforms where the affected versions are installed.