CVE-2022-3049: Use after free in SplitScreen
Published Apr 17, 2022
·Updated
Use after free in SplitScreen in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.
Credit
@@ginggilBesel
Affected Software
8 affected componentsFixes available
Google Chrome<105.0.5195.52
105.0.5195.52
Google Chrome<105.0.5195.52
Google Chrome OS
Google Linux And Chrome Os
fedoraproject fedora=37
All of the following
Google Chrome<105.0.5195.52
Any of the following
Google Chrome OS
Google Linux And Chrome Os
Event History
Apr 17, 2022
CVE Published
12:00 AM
Sep 26, 2022
CVE Published
via MITRE·03:01 PM
Data Sourced
via MITRE·03:01 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-3049.
2
What is the severity of CVE-2022-3049?
CVE-2022-3049 has a severity value of 8.8 (high).
3
Which software versions are affected by CVE-2022-3049?
Versions prior to 105.0.5195.52 of Google Chrome on Chrome OS, Lacros are affected by CVE-2022-3049.
4
How can a remote attacker take advantage of CVE-2022-3049?
A remote attacker can potentially exploit heap corruption by convincing a user to engage in specific UI interactions via a crafted HTML page.
5
Is Google Chrome OS vulnerable to CVE-2022-3049?
No, Google Chrome OS is not vulnerable to CVE-2022-3049.