CVE-2022-3075: Google Chromium Mojo Insufficient Data Validation Vulnerability
Chromium: CVE-2022-3075 Insufficient data validation in Mojo
Other sources
Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
— CISA
Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware of reportsrts that an exploit for CVE-2022-3075 exists in the wild.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 105.0.5195.102 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 105.0.1343.27 - Upgrade
Upgrade
Microsoft Edge Betato a version that resolves this vulnerability.Fixed in 105.0.1343.27
Event History
Frequently Asked Questions
What is CVE-2022-3075?
CVE-2022-3075 is a vulnerability in Google Chromium Mojo that allows for insufficient data validation.
Which web browsers are affected by CVE-2022-3075?
Web browsers that utilize Chromium, including Google Chrome and Microsoft Edge, are affected by CVE-2022-3075.
What is the severity of CVE-2022-3075?
The severity of CVE-2022-3075 is currently unknown.
How can I fix CVE-2022-3075 in Microsoft Edge (Chromium-based)?
To fix CVE-2022-3075 in Microsoft Edge (Chromium-based), update to version 105.0.1343.27 or later.
Where can I find more information about CVE-2022-3075?
You can find more information about CVE-2022-3075 at the following references: (1) https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop.html, (2) https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-3075