CVE-2022-3075 is a critical vulnerability in Google Chrome, specifically affecting versions prior to 105.0.5195.102, as well as Fedora Project's Chrome and Fedora. It stems from insufficient data validation in Mojo, allowing a remote attacker to potentially escape the sandbox via a crafted HTML page if the renderer process is compromised. With a CVSS score of 9.6 (CRITICAL), this vulnerability has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. Notably, it is actively exploited (KEV listed), has garnered significant community discussion (19 mentions), and has been widely covered in media (9 articles), despite no public exploit code being available on Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 105.0.5195.102CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.