CVE-2022-3046 is a use-after-free vulnerability in Google Chrome's Browser Tag, affecting versions prior to 105.0.5195.52, as well as Fedora Project's Chrome and Fedora distributions. An attacker could exploit this by convincing a user to install a malicious extension, leading to heap corruption through a crafted HTML page. This vulnerability carries a high CVSS score of 8.8, indicating a network-based attack with low complexity, requiring user interaction, and potentially leading to high confidentiality, integrity, and availability impacts. While it has not been added to CISA's KEV catalog and no public exploit code is available, it has garnered some community discussion and media coverage, including a mention in Microsoft's September 2022 Patch Tuesday fixes.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 105.0.5195.52CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.