CVE-2022-1856 is a use-after-free vulnerability in Google Chrome's User Education component, affecting versions prior to 102.0.5005.61. This flaw carries a high severity CVSS score of 8.8, indicating that an unauthenticated attacker could achieve high impact on confidentiality, integrity, and availability by convincing a user to install a malicious extension, potentially leading to heap corruption. While the vulnerability is not listed on CISA's KEV catalog and there is no public exploit code available, it has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 102.0.5005.61CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.