Heap-based buffer overflow in Google Chromium - CVE-2022-1143
Published: March 29, 2022 / Updated: April 2, 2022
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in WebUI. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Affected software
Google Chrome
Microsoft Edge
Gentoo Linux
Chrome OS
chromium (Debian package)
www-client/google-chrome
dev-qt/qtwebengine
www-client/chromium
How to mitigate CVE-2022-1143
Google Chrome - update to 100.0.4896.60
chromium (Debian package) - update to 100.0.4896.60-1~deb11u1
Microsoft Edge - update to 100.0.1185.29
Chrome OS - update to 96.0.4664.206
www-client/google-chrome - update to 101.0.1210.47
dev-qt/qtwebengine - update to 103.0.5060.53
www-client/chromium - update to 103.0.5060.53