Exploitation of CVE-2022-3038 in Google Chrome
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2022-3038 to their Known Exploited Vulnerabilities Catalog
Summary
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2022-3038 to their Known Exploited Vulnerabilities Catalog
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Google released a security update to address a High severity use-after-free vulnerability tracked as CVE-2022-3038 in August 2022. This vulnerability affects Google for Windows, Mac, and Linux, and has a CVSSv3 score of 8.8. A remote attacker could exploit this heap corruption vulnerability via a crafted HTML page. The US Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to their Known Exploited Vulnerability Catalog in March 2023.
Exploitation in the wild for CVE-2022-3038
CISA has added CVE-2022-3038 to their Known Exploited Vulnerabilities Catalog.
Remediation advice
Affected organisations are encouraged to review the Chrome Release relating to this vulnerability and the latest Chrome Release and apply any relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 3 April 2023 2:24 pm