CVE-2022-1484 is a high-severity heap buffer overflow vulnerability affecting Google Chrome versions prior to 101.0.4951.41, specifically within the Web UI Settings. This flaw allows a remote attacker to potentially corrupt the heap and execute arbitrary code by enticing a user to visit a specially crafted HTML page. With a CVSS score of 8.8 (HIGH), exploitation requires user interaction but can lead to high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or Nuclei, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 101.0.4951.41CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.