8.8
CVSSv3

CVE-2022-3052

Published: 26/09/2022 Updated: 07/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Heap buffer overflow in Window Manager in Google Chrome on Chrome OS, Lacros before 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

google linux and chrome os -

fedoraproject fedora 37

Vendor Advisories

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure For the stable distribution (bullseye), these problems have been fixed in version 1050519552-1~deb11u1 We recommend that you upgrade your chromium packages For the detailed security status of ...
The Stable channel is being updated to 10505195112 (Platform version: 14989850) for most ChromeOS devices and will be rolled out over the next few daysFor Chrome browser fixes, see the Chrome Desktop release announcementIf you find new issues, please let us know one of the following ways:File a bug Visit our Chrome O ...
LTS-102 has been updated in the LTS channel to 10205005182 (Platform Version: 146951350) for most ChromeOS devices Want to know more about Long-term Support? Click hereThis update contains multiple Security fixes, including:1340253  Critical CVE-2022-3038 Use after free in Network Service1051198  ...
The Chrome team is delighted to announce the promotion of Chrome 105 to the stable channel for Windows, Mac and Linux This will roll out over the coming days/weeksChrome 1050519552 ( Mac/linux) and 1050519552/53/54( Windows)  contains a number of fixes and improvements -- a list of changes is available in the log W ...

Recent Articles

Chinese snoops use F5, ConnectWise bugs to sell access into top US, UK networks
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Crew may well be working under contract for Beijing

Chinese spies exploited a couple of critical-severity bugs in F5 and ConnectWise equipment earlier this year to sell access to compromised US defense organizations, UK government agencies, and hundreds of other entities, according to Mandiant. The Google-owned threat hunters said they assess, "with moderate confidence," that a crew they track as UNC5174 was behind the exploitation of CVE-2023-46747, a 9.8-out-of-10-CVSS-rated remote code execution bug in the F5 BIG-IP Traffic Management User Int...