Out-of-bounds read in Google Chromium - CVE-2022-0114

 

Out-of-bounds read in Google Chromium - CVE-2022-0114

Published: January 4, 2022 / Updated: January 6, 2022


Vulnerability identifier: #VU59213
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0114
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to crash the browser.

The vulnerability exists due to a boundary condition within the Web Serial component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and crash the browser.


Affected software

Google Chromium
Google Chrome
Microsoft Edge
Gentoo Linux
Fedora
Chrome OS
chromium (Debian package)
chromium

How to mitigate CVE-2022-0114

Update to version 97.0.4692.71.

Google Chromium - update to 97.0.4692.71
Google Chrome - update to 97.0.4692.71
Microsoft Edge - update to 97.0.1072.55
Chrome OS - update to 96.0.4664.202
chromium (Debian package) - update to 97.0.4692.71-0.1~deb11u1
chromium - addressed in versions 99.0.4844.51-1.el7, 99.0.4844.51-1.el8, 99.0.4844.51-1.fc34, 99.0.4844.51-1.fc35, 99.0.4844.51-1.fc36

External References

Related Security Bulletins