CVE-2022-3050 describes a heap buffer overflow vulnerability in the WebUI component of Google Chrome on Chrome OS, affecting versions prior to 105.0.5195.52, as well as Fedora Project distributions. This high-severity flaw (CVSS 8.8) could allow a remote attacker to achieve heap corruption and potentially execute arbitrary code if a user is tricked into specific UI interactions. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and it is not listed in CISA's KEV catalog, its FAUCET Risk Score of 71/100 indicates a significant threat. There is no evidence of active exploitation, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 105.0.5195.52CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.