CVE-2022-2998: Use after free in Browser Creation
Published May 27, 2022
·Updated
Use after free in Browser Creation in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who had convinced a user to engage in a specific UI interaction to potentially exploit heap corruption via a crafted HTML page.
Credit
Sergei Glazunov(Google Project Zero)
Affected Software
2 affected componentsFixes available
Google Chrome<104.0.5112.101
104.0.5112.101
Google Chrome<104.0.5112.101
Event History
May 27, 2022
CVE Published
12:00 AM
Sep 26, 2022
CVE Published
via MITRE·03:01 PM
Data Sourced
via MITRE·03:01 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-2998?
CVE-2022-2998 has a severity rating of high due to the potential for remote code execution via heap corruption.
2
How do I fix CVE-2022-2998?
To fix CVE-2022-2998, update Google Chrome to version 104.0.5112.101 or later.
3
Who is affected by CVE-2022-2998?
Users of Google Chrome versions prior to 104.0.5112.101 are affected by CVE-2022-2998.
4
What is the nature of the vulnerability in CVE-2022-2998?
CVE-2022-2998 is a use after free vulnerability that can lead to heap corruption.
5
Can CVE-2022-2998 be exploited by an attacker?
Yes, CVE-2022-2998 can be exploited by attackers who convince a user to interact with a specially crafted HTML page.