CVE-2022-3654: Use after free in Layout
Published Sep 19, 2022
·Updated
Use after free in Layout in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Credit
Sergei Glazunov(Google Project Zero)
Affected Software
2 affected componentsFixes available
Google Chrome<107.0.5304.62
107.0.5304.62
Google Chrome<107.0.5304.62
Event History
Sep 19, 2022
CVE Published
12:00 AM
Nov 1, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-3654?
The severity of CVE-2022-3654 is classified as High.
2
What versions of Google Chrome are affected by CVE-2022-3654?
CVE-2022-3654 affects Google Chrome versions prior to 107.0.5304.62.
3
How do I fix CVE-2022-3654?
To fix CVE-2022-3654, update Google Chrome to version 107.0.5304.62 or later.
4
What type of attack can exploit CVE-2022-3654?
CVE-2022-3654 can be exploited through a crafted HTML page leading to potential heap corruption.
5
Is CVE-2022-3654 a use after free vulnerability?
Yes, CVE-2022-3654 is a use after free vulnerability in the Layout component of Google Chrome.