CVE-2022-1142
published 2022-07-23CVE-2022-1142: Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to…
PriorityP343high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.77%
51.8th percentile
Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 100.0.4896.60-1~deb11u1 | 100.0.4896.60-1~deb11u1 |
| chromium | chromium | >= 0 < 100.0.4896.60-1 | 100.0.4896.60-1 |
| chromium | chromium | >= 0 < 100.0.4896.60-1 | 100.0.4896.60-1 |
| chromium | chromium | >= 0 < 100.0.4896.60-1 | 100.0.4896.60-1 |
| debian | chromium | < chromium 100.0.4896.60-1 (bookworm) | chromium 100.0.4896.60-1 (bookworm) |
| chrome | < 100.0.4896.60 | 100.0.4896.60 | |
| chrome | >= unspecified < 100.0.4896.60 | 100.0.4896.60 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Long Term Support Channel Update: CVE-2022-1142
vendor_chrome·2022-04-15·CVSS 8.8
CVE-2022-1142 [MEDIUM] Long Term Support Channel Update: CVE-2022-1142
Long Term Support Channel Update
CVE-2022-1142: Heap buffer overflow in WebUI. 1304545 Medium CVE-2022-1145: Use after free in Extensions
Severity: medium
Debian
CVE-2022-1142: chromium - Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a ...
vendor_debian·2022·CVSS 8.8
CVE-2022-1142 [HIGH] CVE-2022-1142: chromium - Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a ...
Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.
Scope: local
bookworm: resolved (fixed in 100.0.4896.60-1)
bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1)
forky: resolved (fixed in 100.0.4896.60-1)
sid: resolved (fixed in 100.0.4896.60-1)
trixie: resolved (fixed in 100.0.4896.60-1)
GHSA
GHSA-wp7f-3m97-grc2: Heap buffer overflow in WebUI in Google Chrome prior to 100
ghsa_unreviewed·2022-07-24
CVE-2022-1142 [HIGH] CWE-787 GHSA-wp7f-3m97-grc2: Heap buffer overflow in WebUI in Google Chrome prior to 100
Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.
OSV
CVE-2022-1142: Heap buffer overflow in WebUI in Google Chrome prior to 100
osv·2022-07-23·CVSS 8.8
CVE-2022-1142 [HIGH] CVE-2022-1142: Heap buffer overflow in WebUI in Google Chrome prior to 100
Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_29.htmlhttps://crbug.com/1303613https://security.gentoo.org/glsa/202208-25https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_29.htmlhttps://crbug.com/1303613https://security.gentoo.org/glsa/202208-25
2022-07-23
Published