CVE-2022-4177 is a high-severity use-after-free vulnerability in Google Chrome, affecting versions prior to 108.0.5359.71. An attacker could exploit this by convincing a user to install a malicious Chrome Extension, leading to heap corruption and potential high impact on confidentiality, integrity, and availability. The vulnerability has a CVSS score of 8.8 (High) and requires user interaction. There is no public exploit code available, nor is it listed in CISA's KEV catalog, but it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 108.0.5359.71CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.