CVE-2022-4191 is a use-after-free vulnerability in Google Chrome's Sign-In component, affecting versions prior to 108.0.5359.71. A remote attacker could exploit this by convincing a user to engage in specific UI interaction, leading to heap corruption during profile destruction. With a CVSS score of 8.8 (HIGH), this vulnerability has a network attack vector, low attack complexity, and high potential impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV: No) or public exploit code (Metasploit, Nuclei, ExploitDB: None), it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 108.0.5359.71CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.