CVE-2022-3653 is a high-severity heap buffer overflow vulnerability affecting Google Chrome versions prior to 107.0.5304.62. A remote attacker could exploit this flaw by enticing a user to visit a crafted HTML page, potentially leading to heap corruption. The vulnerability carries a CVSS score of 8.8 (High), indicating a network-based attack with low complexity, requiring user interaction, and resulting in high impacts to confidentiality, integrity, and availability. While Google has paid out bounties for this vulnerability, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion beyond a single media article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 107.0.5304.62CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.