First published: Thu Sep 08 2022(Updated: )
Out of bounds write in Lacros Graphics in Google Chrome on Chrome OS and Lacros prior to 108.0.5359.71 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity: High)
Credit: @ginggilBesel chrome-cve-admin@google.com chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <108.0.5359.71 | |
Google Chrome OS | ||
Google Linux And Chrome Os | ||
Google Chrome | <108.0.5359.71 | 108.0.5359.71 |
All of | ||
Google Chrome | <108.0.5359.71 | |
Any of | ||
Google Chrome OS | ||
Google Linux And Chrome Os |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2022-4176.
The severity of CVE-2022-4176 is High (8.8).
Google Chrome on Chrome OS and Lacros prior to 108.0.5359.71 are affected by CVE-2022-4176.
A remote attacker who convinces a user to engage in specific UI interactions can potentially exploit heap corruption via UI interactions in Lacros Graphics in Google Chrome.
Update to Google Chrome version 108.0.5359.71 or later to fix CVE-2022-4176.