CVE-2022-3657: Use after free in Extensions
Published Aug 9, 2022
·Updated
Use after free in Extensions in Google Chrome prior to 107.0.5304.62 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)
Credit
Omri Bushari, Talon Cyber Security
Affected Software
2 affected componentsFixes available
Google Chrome<107.0.5304.62
107.0.5304.62
Google Chrome<107.0.5304.62
Event History
Aug 9, 2022
CVE Published
12:00 AM
Nov 1, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-3657?
CVE-2022-3657 has a medium severity level as classified by Chromium security.
2
How do I fix CVE-2022-3657?
To fix CVE-2022-3657, update Google Chrome to version 107.0.5304.62 or later.
3
What type of vulnerability is CVE-2022-3657?
CVE-2022-3657 is a use after free vulnerability found in the Extensions of Google Chrome.
4
Who is affected by CVE-2022-3657?
Users of Google Chrome versions prior to 107.0.5304.62 are affected by CVE-2022-3657.
5
What could an attacker do with CVE-2022-3657?
An attacker could potentially exploit heap corruption by convincing a user to install a malicious Chrome extension.