CVE-2022-2295 is a high-severity type confusion vulnerability in the V8 JavaScript engine of Google Chrome, affecting versions prior to 103.0.5060.114, as well as related Fedora and Enterprise Linux packages. This flaw allows a remote attacker to potentially exploit heap corruption by enticing a user to visit a crafted HTML page. With a CVSS score of 8.8, it poses a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Notably, this vulnerability was actively exploited in the wild at the time of its disclosure, despite the absence of public exploit code in Metasploit or ExploitDB, and garnered substantial media coverage and community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 103.0.5060.114CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:8.0:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.