CVE-2022-2010 — Out-of-bounds Read in Google Chrome
CWE-125 — Out-of-bounds ReadCWE-20 — Improper Input ValidationCWE-119 — Improper Restriction of Operations within the Bounds of a Memory BufferCWE-22 — Path TraversalCWE-805 — Buffer Access with Incorrect Length ValueCWE-77 — Command InjectionCWE-94 — Code InjectionCWE-264CWE-787 — Out-of-bounds Write29 documents10 sources
Severity
9.3CRITICALNVD
CISA10.0CISA9.8CISA8.8CISA7.8CISA7.5CISA7.3CISA5.3
EPSS
1.1%
top 21.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 28
Latest updateSep 15
Description
Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:HExploitability: 2.8 | Impact: 5.8
Affected Packages6 packages
Also affects: Fedora 37
🔴Vulnerability Details
2📋Vendor Advisories
22🕵️Threat Intelligence
2Qualys▶
June 2022 Patch Tuesday | Microsoft Releases 55 Vulnerabilities With 3 Critical; Adobe Releases 6 Advisories, 46 Vulnerabilities With 40 Critical.↗2022-06-14
Qualys▶
June 2022 Patch Tuesday | Microsoft Releases 55 Vulnerabilities With 3 Critical; Adobe Releases 6 Advisories, 46 Vulnerabilities With 40 Critical. | Qualys↗2022-06-14