CVE-2022-0307

Description

Use after free in Optimization Guide in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.96

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-4098,CVE-2021-4099,CVE-2021-4100,CVE-2021-4101,CVE-2021-4102 are fixed in Google Chrome (96.0.4664.110)Windows
Vulnerabilities CVE-2021-4098,CVE-2021-4099,CVE-2021-4100,CVE-2021-4101,CVE-2021-4102 are fixed in Google Chrome (x64) (96.0.4664.110)Windows
Multiple vulnerabilities fixed in Google Chrome (x64) (97.0.4692.99)Windows
Multiple vulnerabilities fixed in Google Chrome (97.0.4692.99)Windows
Multiple vulnerabilities fixed in Microsoft Edge for chromium business (x64) (97.0.1072.69)Windows
Multiple vulnerabilities fixed in Microsoft Edge for chromium business (97.0.1072.69)Windows
Multiple vulnerabilities are fixed in Google Chrome For Mac 96.0.4664.110Mac
Multiple vulnerabilities are fixed in Google Chrome For Mac 97.0.4692.99Mac
chromium security update(DSA-5054-1) chromium_97.0.4692.99-1~deb11u2_amd64.debLinux
Multiple vulnerabilities Affected in Chrome for Centos 97.0.4692.98Linux
Multiple vulnerabilities Affected in Chrome for Debian 97.0.4692.98Linux
Multiple vulnerabilities Affected in Chrome for RedHat 97.0.4692.98Linux
Multiple vulnerabilities Affected in Chrome for Suse 97.0.4692.98Linux
Multiple vulnerabilities Affected in Chrome for Ubuntu 97.0.4692.98Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-322805Google Chrome (96.0.4664.110)
PATCH-322806Google Chrome (x64) (96.0.4664.110)
PATCH-323269Google Chrome (x64) (97.0.4692.99)
PATCH-323268Google Chrome (97.0.4692.99)
PATCH-109332Microsoft Edge for chromium business (99.0.1150.30) (x64)
PATCH-109333Microsoft Edge for chromium business (99.0.1150.30) (x86)
PATCH-609673Google Chrome for Mac (132.0.6834.83, 132.0.6834.84)
PATCH-609673Google Chrome for Mac (132.0.6834.83, 132.0.6834.84)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234