CVE-2022-2743
published 2023-01-02CVE-2022-2743: Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in…
PriorityP344high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.54%
42.3th percentile
Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific UI interactions to perform an out of bounds memory write via crafted UI interactions. (Chrome security severity: High)
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 104.0.5112.79-1~deb11u1 | 104.0.5112.79-1~deb11u1 |
| chromium | chromium | >= 0 < 104.0.5112.79-1 | 104.0.5112.79-1 |
| chromium | chromium | >= 0 < 104.0.5112.79-1 | 104.0.5112.79-1 |
| chromium | chromium | >= 0 < 104.0.5112.79-1 | 104.0.5112.79-1 |
| debian | chromium | < chromium 104.0.5112.79-1 (bookworm) | chromium 104.0.5112.79-1 (bookworm) |
| chrome | < 104.0.5112.79 | 104.0.5112.79 | |
| chrome | >= unspecified < 104.0.5112.79 | 104.0.5112.79 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 103.0.5060.134 on ChromeOS Window Manager out-of-bounds write (EUVD-2022-34985)
vuldb·2026-05-27·CVSS 8.8
CVE-2022-2743 [HIGH] Google Chrome up to 103.0.5060.134 on ChromeOS Window Manager out-of-bounds write (EUVD-2022-34985)
A vulnerability identified as critical has been detected in Google Chrome on ChromeOS. Affected by this vulnerability is an unknown functionality of the component Window Manager. This manipulation causes out-of-bounds write.
This vulnerability is handled as CVE-2022-2743. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
GHSA
GHSA-6qpx-r9mr-g6jw: Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104
ghsa_unreviewed·2023-01-03
CVE-2022-2743 [HIGH] CWE-190 GHSA-6qpx-r9mr-g6jw: Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104
Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific UI interactions to perform an out of bounds memory write via crafted UI interactions. (Chrome security severity: High)
OSV
CVE-2022-2743: Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104
osv·2023-01-02·CVSS 8.8
CVE-2022-2743 [HIGH] CVE-2022-2743: Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104
Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific UI interactions to perform an out of bounds memory write via crafted UI interactions. (Chrome security severity: High)
Debian
CVE-2022-2743: chromium - Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prio...
vendor_debian·2022·CVSS 8.8
CVE-2022-2743 [HIGH] CVE-2022-2743: chromium - Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prio...
Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific UI interactions to perform an out of bounds memory write via crafted UI interactions. (Chrome security severity: High)
Scope: local
bookworm: resolved (fixed in 104.0.5112.79-1)
bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1)
forky: resolved (fixed in 104.0.5112.79-1)
sid: resolved (fixed in 104.0.5112.79-1)
trixie: resolved (fixed in 104.0.5112.79-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-02
Published