CVE-2022-3842: Use after free in Passwords
Published Aug 12, 2022
·Updated
Use after free in Passwords in Google Chrome prior to 105.0.5195.125 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Credit
Sergei Glazunov(Google Project Zero)
Affected Software
2 affected componentsFixes available
Google Chrome<105.0.5195.125
105.0.5195.125
Google Chrome<105.0.5195.125
Event History
Aug 12, 2022
CVE Published
12:00 AM
Jan 2, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-3842?
The severity of CVE-2022-3842 is classified as High.
2
How do I fix CVE-2022-3842?
To fix CVE-2022-3842, update Google Chrome to version 105.0.5195.125 or later.
3
What impact does CVE-2022-3842 have on users?
CVE-2022-3842 allows a remote attacker to potentially exploit heap corruption through a crafted HTML page.
4
Which versions of Google Chrome are affected by CVE-2022-3842?
CVE-2022-3842 affects all versions of Google Chrome prior to 105.0.5195.125.
5
Who is the vendor of the affected software for CVE-2022-3842?
The vendor of the affected software for CVE-2022-3842 is Google.