CVE-2022-2011 is a high-severity use-after-free vulnerability in ANGLE, affecting Google Chrome versions prior to 102.0.5005.115, as well as Fedora Project's Chrome and Fedora. This flaw allows a remote attacker to potentially achieve heap corruption by enticing a user to visit a specially crafted HTML page. With a CVSS score of 8.8, it presents a high risk for confidentiality, integrity, and availability, requiring user interaction but with low attack complexity. While not currently listed on CISA's KEV catalog and lacking public exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 102.0.5005.115CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.