Use-after-free in Google Chromium - CVE-2022-3659
Published: October 26, 2022
Vulnerability identifier: #VU68736
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-3659
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Accessibility in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
Affected software
Google Chromium
Google Chrome
Debian Linux
Chrome OS
chromium (Debian package)
Google Chrome
Debian Linux
Chrome OS
chromium (Debian package)
How to mitigate CVE-2022-3659
Update to version 107.0.5304.62.
Google Chromium - update to 107.0.5304.62
Google Chrome - update to 107.0.5304.62
chromium (Debian package) - update to 107.0.5304.68-1~deb11u1
Chrome OS - update to 107.0.5304.92
Google Chrome - update to 107.0.5304.62
chromium (Debian package) - update to 107.0.5304.68-1~deb11u1
Chrome OS - update to 107.0.5304.92