Use-after-free in Google Chromium - CVE-2022-3038
Published: August 30, 2022 / Updated: March 30, 2023
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Network Service component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Note, the vulnerability is known to be exploited in the wild.
Affected software
Google Chrome
Microsoft Edge
Debian Linux
Gentoo Linux
Fedora
Chrome OS
www-client/microsoft-edge
chromium (Debian package)
www-client/chromium
www-client/chromium-bin
www-client/google-chrome
chromium
How to mitigate CVE-2022-3038
Google Chrome - update to 105.0.5195.52
Microsoft Edge - update to 105.0.1343.25
Chrome OS - addressed in versions 102.0.5005.182, 102.0.5005.189
www-client/microsoft-edge - update to 105.0.1343.42
chromium (Debian package) - update to 105.0.5195.52-1~deb11u1
www-client/chromium - update to 105.0.5195.125
www-client/chromium-bin - update to 105.0.5195.125
www-client/google-chrome - update to 105.0.5195.125
chromium - addressed in versions 105.0.5195.125-2.el8, 105.0.5195.125-2.el9, 105.0.5195.125-2.fc35, 105.0.5195.125-2.fc36, 105.0.5195.125-2.fc37
External References
- https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_30.html
- https://crbug.com/1340253
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-3038
- https://blog.google/threat-analysis-group/spyware-vendors-use-0-days-and-n-days-against-popular-platforms/
Related Security Bulletins
- Multiple vulnerabilities in Google Chrome
- Multiple vulnerabilities in Microsoft Edge
- Debian update for chromium
- Gentoo update for Chromium, Google Chrome, Microsoft Edge
- Multiple vulnerabilities in Google ChromeOS
- Remote code execution in Google Chrome OS
- Fedora 36 update for chromium
- Fedora 35 update for chromium
- Fedora 37 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 9 update for chromium