CVE-2022-3449
Gentoo Linux Security Advisory 202305-10
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Use after free in Safe Browsing in Google Chrome prior to 106.0.5249.119 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
Use-After-Free en Navegación Segura en Google Chrome anterior a la versión 106.0.5249.119 permitió a un atacante que convenció a un usuario de instalar una extensión maliciosa para explotar potencialmente la corrupción del montón a través de una extensión de Chrome manipulada. (Severidad de seguridad de Chrome: Alta)
Multiple vulnerabilities have been found in Chromium and its derivatives, the worst of which could result in remote code execution. Versions less than 109.0.5414.74-r1>= are affected.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2022-10-11 CVE Reserved
- 2022-10-13 CVE Published
- 2024-10-24 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-416: Use After Free
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://chromereleases.googleblog.com/2022/10/stable-channel-update-for-desktop_11.html | 2023-05-03 | |
https://crbug.com/1364662 | 2023-05-03 | |
https://security.gentoo.org/glsa/202305-10 | 2023-05-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | < 106.0.5249.119 Search vendor "Google" for product "Chrome" and version " < 106.0.5249.119" | - |
Affected
|