CVE-2022-2587
published 2022-08-12CVE-2022-2587: Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102.0.5005.125 allowed a remote attacker to potentially exploit heap…
PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.70%
49.7th percentile
Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102.0.5005.125 allowed a remote attacker to potentially exploit heap corruption via crafted audio metadata.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | chromium | — | — |
| chrome | < 102.0.5005.125 | 102.0.5005.125 | |
| chrome | >= unspecified < 102.0.5005.125 | 102.0.5005.125 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_debian9.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for ChromeOS: CVE-2022-2587
vendor_chrome·2022-06-15·CVSS 9.8
CVE-2022-2587 [HIGH] Stable Channel Update for ChromeOS: CVE-2022-2587
Stable Channel Update for ChromeOS
CVE-2022-2587: Out of bounds write in OS Audio Server. Reported by Jonathan Bar Or, @yo_yo_yo_jbo on 2022-04-28 If you find new issues, plea let us know one of the following ways File a bug Visit our Chrome OS communities General: Chromebook Help Community Beta Specific: ChromeOS Beta Help Community Report an issue or send feedback on Chrome Interested in switching channels? Find out how
Severity: high
Debian
CVE-2022-2587: chromium - Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prio...
vendor_debian·2022·CVSS 9.8
CVE-2022-2587 [CRITICAL] CVE-2022-2587: chromium - Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prio...
Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102.0.5005.125 allowed a remote attacker to potentially exploit heap corruption via crafted audio metadata.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-r6m5-2jxc-mqrv: Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102
ghsa_unreviewed·2022-08-13
CVE-2022-2587 [CRITICAL] CWE-787 GHSA-r6m5-2jxc-mqrv: Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102
Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102.0.5005.125 allowed a remote attacker to potentially exploit heap corruption via crafted audio metadata.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-12
Published