CVE-2022-1144
published 2022-07-23CVE-2022-1144: Use after free in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to…
PriorityP342high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.69%
49.0th percentile
Use after free in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 100.0.4896.60-1~deb11u1 | 100.0.4896.60-1~deb11u1 |
| chromium | chromium | >= 0 < 100.0.4896.60-1 | 100.0.4896.60-1 |
| chromium | chromium | >= 0 < 100.0.4896.60-1 | 100.0.4896.60-1 |
| chromium | chromium | >= 0 < 100.0.4896.60-1 | 100.0.4896.60-1 |
| debian | chromium | < chromium 100.0.4896.60-1 (bookworm) | chromium 100.0.4896.60-1 (bookworm) |
| chrome | < 100.0.4896.60 | 100.0.4896.60 | |
| chrome | >= unspecified < 100.0.4896.60 | 100.0.4896.60 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Long Term Support Channel Update: CVE-2022-1143
vendor_chrome·2022-04-15·CVSS 8.8
CVE-2022-1143 [MEDIUM] Long Term Support Channel Update: CVE-2022-1143
Long Term Support Channel Update
CVE-2022-1143: Heap buffer overflow in WebUI. 1304145 Medium CVE-2022-1144: Use after free in WebUI
Severity: medium
Debian
CVE-2022-1144: chromium - Use after free in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote...
vendor_debian·2022·CVSS 8.8
CVE-2022-1144 [HIGH] CVE-2022-1144: chromium - Use after free in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote...
Use after free in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.
Scope: local
bookworm: resolved (fixed in 100.0.4896.60-1)
bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1)
forky: resolved (fixed in 100.0.4896.60-1)
sid: resolved (fixed in 100.0.4896.60-1)
trixie: resolved (fixed in 100.0.4896.60-1)
GHSA
GHSA-grg9-xmwf-c24g: Use after free in WebUI in Google Chrome prior to 100
ghsa_unreviewed·2022-07-24
CVE-2022-1144 [HIGH] CWE-416 GHSA-grg9-xmwf-c24g: Use after free in WebUI in Google Chrome prior to 100
Use after free in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.
OSV
CVE-2022-1144: Use after free in WebUI in Google Chrome prior to 100
osv·2022-07-23·CVSS 8.8
CVE-2022-1144 [HIGH] CVE-2022-1144: Use after free in WebUI in Google Chrome prior to 100
Use after free in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_29.htmlhttps://crbug.com/1304145https://security.gentoo.org/glsa/202208-25https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_29.htmlhttps://crbug.com/1304145https://security.gentoo.org/glsa/202208-25
2022-07-23
Published