CVE-2022-3038 is a critical use-after-free vulnerability in Google Chrome's Network Service, affecting Chrome versions prior to 105.0.5195.52, as well as Fedora Project's Chrome and Fedora distributions. This flaw allows a remote attacker to achieve heap corruption by enticing a user to visit a specially crafted HTML page. With a CVSS score of 8.8 (High), it presents a significant risk, enabling high impact to confidentiality, integrity, and availability with low attack complexity. The vulnerability is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, and has garnered substantial community discussion and media coverage, despite the absence of public exploit code in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 105.0.5195.52CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.