First published: Mon Jun 06 2022(Updated: )
Use after free in Tab Strip in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interaction.
Credit: @ginggilBesel chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <105.0.5195.52 | |
Google Chrome OS | ||
Google Linux And Chrome Os | ||
Fedoraproject Fedora | =37 | |
Google Chrome | <105.0.5195.52 | 105.0.5195.52 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for the use after free vulnerability in Google Chrome on Chrome OS Lacros is CVE-2022-3071.
The severity of CVE-2022-3071 is high with a CVSS score of 8.8.
Google Chrome on Chrome OS, Lacros prior to version 105.0.5195.52 is affected by CVE-2022-3071.
A remote attacker can potentially exploit CVE-2022-3071 by convincing a user to engage in specific UI interactions that lead to heap corruption via crafted UI interaction.
To fix the use after free vulnerability CVE-2022-3071, update Google Chrome on Chrome OS, Lacros to version 105.0.5195.52 or later.