CVE-2022-2296 is a use-after-free vulnerability in Chrome OS Shell affecting Google Chrome on Chrome OS prior to version 103.0.5060.114. With a CVSS score of 8.8 (High), it allows a remote attacker to potentially exploit heap corruption and achieve high impact on confidentiality, integrity, and availability if a user is convinced to engage in specific UI interactions. While no public exploit code or Metasploit modules are available, this vulnerability has garnered significant community discussion and media coverage, indicating active awareness and potential for real-world exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 103.0.5060.114CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:8.0:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.