CVE-2022-1127 is a use-after-free vulnerability in the QR Code Generator component of Google Chrome versions prior to 100.0.4896.60. A remote attacker could exploit this by convincing a user to engage in specific interactions, potentially leading to heap corruption. This vulnerability carries a high CVSS score of 8.8, indicating a severe impact with high confidentiality, integrity, and availability risks, though it requires user interaction for successful exploitation. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, suggesting it is not actively exploited in the wild. Despite this, it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 100.0.4896.60CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.