CVE-2022-3370 is a high-severity use-after-free vulnerability in Google Chrome's Custom Elements, affecting versions prior to 106.0.5249.91. A remote attacker could exploit this flaw via a crafted HTML page, leading to heap corruption and potentially arbitrary code execution. With a CVSS score of 8.8, it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog, its presence in media coverage and community discussions suggests awareness, though no public exploit code or Metasploit modules are available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 106.0.5249.91CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.