CVE-2022-3042: Use after free in PhoneHub
Published Jun 22, 2022
·Updated
Use after free in PhoneHub in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
koocola@@alo_cook(360 Vulnerability Research Institute), Guang Gong(360 Vulnerability Research Institute)
Affected Software
6 affected componentsFixes available
Google Chrome<105.0.5195.52
105.0.5195.52
Google Chrome<105.0.5195.52
Google Chrome OS
fedoraproject fedora=37
All of the following
Google Chrome<105.0.5195.52
Google Chrome OS
Remediation
Event History
Jun 22, 2022
CVE Published
12:00 AM
Sep 26, 2022
CVE Published
via MITRE·03:01 PM
Data Sourced
via MITRE·03:01 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2022-3042.
2
What is the severity rating of CVE-2022-3042?
CVE-2022-3042 has a severity rating of 8.8 (high).
3
What is the affected software?
The affected software includes Google Chrome on Chrome OS prior to version 105.0.5195.52 and Fedora 37.
4
What is the description of CVE-2022-3042?
CVE-2022-3042 is a use-after-free vulnerability in PhoneHub in Google Chrome on Chrome OS, allowing a remote attacker to potentially exploit heap corruption via a crafted HTML page.
5
How do I fix CVE-2022-3042?
To fix CVE-2022-3042, update Google Chrome to version 105.0.5195.52 or later.