9.8
CVSSv3

CVE-2022-2587

Published: 12/08/2022 Updated: 15/08/2022
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS before 102.0.5005.125 allowed a remote malicious user to potentially exploit heap corruption via crafted audio metadata.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

Recent Articles

Microsoft finds critical hole in operating system that for once isn't Windows
The Register • Thomas Claburn • 01 Jan 1970

Topics Security Off-Prem On-Prem Software Offbeat Vendor Voice Vendor Voice Resources Oh wow, get a load of Google using strcpy() all wrong – strcpy! Haha, you'll never ever catch us doing that How do you choose a Cloud Security Provider?

Microsoft has described a severe ChromeOS security vulnerability that one of its researchers reported to Google in late April. The bug was promptly fixed and, about a month later, merged in ChromeOS code then released on June 15, 2022 and detailed by Redmond in a report released on Friday. Microsoft's write-up is noteworthy both for the severity (9.8 out of 10) of the bug and for flipping of the script – it has tended to be Google, particularly its Project Zero group, that calls attention to b...