CVE-2022-2399
published 2022-07-28CVE-2022-2399: Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
PriorityP343high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.69%
48.9th percentile
Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 100.0.4896.88-1~deb11u1 | 100.0.4896.88-1~deb11u1 |
| chromium | chromium | >= 0 < 100.0.4896.88-1 | 100.0.4896.88-1 |
| chromium | chromium | >= 0 < 100.0.4896.88-1 | 100.0.4896.88-1 |
| chromium | chromium | >= 0 < 100.0.4896.88-1 | 100.0.4896.88-1 |
| debian | chromium | < chromium 100.0.4896.88-1 (bookworm) | chromium 100.0.4896.88-1 (bookworm) |
| chrome | < 100.0.4896.88 | 100.0.4896.88 | |
| chrome | >= unspecified < 100.0.4896.88 | 100.0.4896.88 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2022-2399: chromium - Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allowed a remot...
vendor_debian·2022·CVSS 8.8
CVE-2022-2399 [HIGH] CVE-2022-2399: chromium - Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allowed a remot...
Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 100.0.4896.88-1)
bullseye: resolved (fixed in 100.0.4896.88-1~deb11u1)
forky: resolved (fixed in 100.0.4896.88-1)
sid: resolved (fixed in 100.0.4896.88-1)
trixie: resolved (fixed in 100.0.4896.88-1)
GHSA
GHSA-jh2c-mhx3-j74q: Use after free in WebGPU in Google Chrome prior to 100
ghsa_unreviewed·2022-07-29
CVE-2022-2399 [HIGH] CWE-416 GHSA-jh2c-mhx3-j74q: Use after free in WebGPU in Google Chrome prior to 100
Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
OSV
CVE-2022-2399: Use after free in WebGPU in Google Chrome prior to 100
osv·2022-07-28·CVSS 8.8
CVE-2022-2399 [HIGH] CVE-2022-2399: Use after free in WebGPU in Google Chrome prior to 100
Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Use-after-free condition in Google Chrome WebGPU
blogs_talos·2022-07-14·CVSS 8.8
[HIGH] Vulnerability Spotlight: Use-after-free condition in Google Chrome WebGPU
Piotr Bania of Cisco Talos discovered this vulnerability.
Cisco Talos recently discovered an exploitable use-after-free vulnerability in Google Chrome’s WebGPU standard.
Google Chrome is a cross-platform web browser — and Chromium is the open-source version of the browser that both Google and other software developers use as the basis to build their browsers, as well. This specific vulnerability exists in WebGPU, which is a JavaScript API for processing accelerated 3-D graphics and other functions in the browser. TALOS-2022-1508 (CVE-2022-2399) occurs if the user opens a specially crafted web page in Chrome. That page could trigger a use-after-free condition in the application, which an attacker could then use to manipulate the browser in additional ways.
Cisco Talos worked with Google
Talos
Vulnerability Spotlight: Use-after-free condition in Google Chrome WebGPU
blogs_talos·2022-07-14·CVSS 8.8
[HIGH] Vulnerability Spotlight: Use-after-free condition in Google Chrome WebGPU
## Vulnerability Spotlight: Use-after-free condition in Google Chrome WebGPU
Piotr Bania of Cisco Talos discovered this vulnerability.
Cisco Talos recently discovered an exploitable use-after-free vulnerability in Google Chrome’s WebGPU standard.
Google Chrome is a cross-platform web browser — and Chromium is the open-source version of the browser that both Google and other software developers use as the basis to build their browsers, as well. This specific vulnerability exists in WebGPU, which is a JavaScript API for processing accelerated 3-D graphics and other functions in the browser. TALOS-2022-1508 (CVE-2022-2399) occurs if the user opens a specially crafted web page in Chrome. That page could trigger a use-after-free condition in the application, which an attacker could then use
2022-07-28
Published