CVE-2022-4175 is a high-severity use-after-free vulnerability in Google Chrome's Camera Capture component, affecting versions prior to 108.0.5359.71. A remote attacker could exploit this flaw via a crafted HTML page, potentially leading to heap corruption and allowing for high impact to confidentiality, integrity, and availability. While the vulnerability has a CVSS score of 8.8 and a FAUCET Risk Score of 68/100, there is currently no evidence of active exploitation, nor are there public exploit modules available in Metasploit or Nuclei. Community discussion and media coverage are minimal, with only one mention and one article identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 108.0.5359.71CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.