CVE-2022-1641
published 2022-07-26CVE-2022-1641: Use after free in Web UI Diagnostics in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific…
PriorityP343high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.90%
56.0th percentile
Use after free in Web UI Diagnostics in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interaction.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 101.0.4951.64-1~deb11u1 | 101.0.4951.64-1~deb11u1 |
| chromium | chromium | >= 0 < 101.0.4951.64-1 | 101.0.4951.64-1 |
| chromium | chromium | >= 0 < 101.0.4951.64-1 | 101.0.4951.64-1 |
| chromium | chromium | >= 0 < 101.0.4951.64-1 | 101.0.4951.64-1 |
| debian | chromium | < chromium 101.0.4951.64-1 (bookworm) | chromium 101.0.4951.64-1 (bookworm) |
| chrome | < 101.0.4951.64 | 101.0.4951.64 | |
| chrome | >= unspecified < 101.0.4951.64 | 101.0.4951.64 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
cisa7.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2022-1639
vendor_chrome·2022-05-10·CVSS 8.8
CVE-2022-1639 [HIGH] Stable Channel Update for Desktop: CVE-2022-1639
Stable Channel Update for Desktop
CVE-2022-1639: Use after free in ANGLE. Reported by SeongHwan Park (SeHwa) on 2022-04-19 [$TBD][ 1320592 ] High CVE-2022-1640: Use after free in Sharing
Reported by Weipeng Jiang (@Krace) and Guang Gong of 360 Vulnerability Research Institute on 2022-04-28 [$5000][ 1305068 ] Medium CVE-2022-1641: Use after free in Web UI Diagnostics
Severity: high
Debian
CVE-2022-1641: chromium - Use after free in Web UI Diagnostics in Google Chrome on Chrome OS prior to 101....
vendor_debian·2022·CVSS 8.8
CVE-2022-1641 [HIGH] CVE-2022-1641: chromium - Use after free in Web UI Diagnostics in Google Chrome on Chrome OS prior to 101....
Use after free in Web UI Diagnostics in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interaction.
Scope: local
bookworm: resolved (fixed in 101.0.4951.64-1)
bullseye: resolved (fixed in 101.0.4951.64-1~deb11u1)
forky: resolved (fixed in 101.0.4951.64-1)
sid: resolved (fixed in 101.0.4951.64-1)
trixie: resolved (fixed in 101.0.4951.64-1)
CISA
Microsoft Office Memory Corruption Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2015-1641 [HIGH] CWE-399 Microsoft Office Memory Corruption Vulnerability
Vulnerability: Microsoft Office Memory Corruption Vulnerability
Affected: Microsoft Office
Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-1641
Remediation Due Date: 2022-05-03
GHSA
GHSA-fqcp-q7w4-qwrv: Use after free in Web UI Diagnostics in Google Chrome on Chrome OS prior to 101
ghsa_unreviewed·2022-07-27
CVE-2022-1641 [HIGH] CWE-416 GHSA-fqcp-q7w4-qwrv: Use after free in Web UI Diagnostics in Google Chrome on Chrome OS prior to 101
Use after free in Web UI Diagnostics in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interaction.
OSV
CVE-2022-1641: Use after free in Web UI Diagnostics in Google Chrome on Chrome OS prior to 101
osv·2022-07-26·CVSS 8.8
CVE-2022-1641 [HIGH] CVE-2022-1641: Use after free in Web UI Diagnostics in Google Chrome on Chrome OS prior to 101
Use after free in Web UI Diagnostics in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interaction.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_10.htmlhttps://crbug.com/1305068https://security.gentoo.org/glsa/202208-25https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_10.htmlhttps://crbug.com/1305068https://security.gentoo.org/glsa/202208-25
2022-07-26
Published