CVE-2022-2606 is a use-after-free vulnerability in the Managed devices API of Google Chrome, affecting versions prior to 104.0.5112.79, as well as Fedora Project's Chrome and Fedora. This high-severity vulnerability (CVSS 8.8) allows a remote attacker to potentially exploit heap corruption via a crafted HTML page, provided a user is convinced to enable a specific Enterprise policy. While there is no evidence of active exploitation or publicly available exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, including a mention in Microsoft's August 2022 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 104.0.5112.79CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.