CVE-2022-3309
published 2022-11-01CVE-2022-3309: Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to engage in specific UI…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.58%
44.5th percentile
Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: Medium)
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 106.0.5249.61-1~deb11u1 | 106.0.5249.61-1~deb11u1 |
| chromium | chromium | >= 0 < 106.0.5249.61-1 | 106.0.5249.61-1 |
| chromium | chromium | >= 0 < 106.0.5249.61-1 | 106.0.5249.61-1 |
| chromium | chromium | >= 0 < 106.0.5249.61-1 | 106.0.5249.61-1 |
| debian | chromium | < chromium 106.0.5249.61-1 (bookworm) | chromium 106.0.5249.61-1 (bookworm) |
| chrome | < 106.0.5249.62 | 106.0.5249.62 | |
| chrome | >= unspecified < 106.0.5249.62 | 106.0.5249.62 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv6.5MEDIUM
cisa7.8HIGH
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4rhq-r59j-x4fc: Use after free in assistant in Google Chrome on ChromeOS prior to 106
ghsa_unreviewed·2022-11-02
CVE-2022-3309 [MEDIUM] CWE-416 GHSA-4rhq-r59j-x4fc: Use after free in assistant in Google Chrome on ChromeOS prior to 106
Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via specific UI gestures. (Chrome security severity: Medium)
OSV
CVE-2022-3309: Use after free in assistant in Google Chrome on ChromeOS prior to 106
osv·2022-11-01·CVSS 6.5
CVE-2022-3309 [MEDIUM] CVE-2022-3309: Use after free in assistant in Google Chrome on ChromeOS prior to 106
Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: Medium)
Chrome
Stable Channel Update for Desktop: CVE-2022-3308
vendor_chrome·2022-09-27·CVSS 7.4
CVE-2022-3308 [MEDIUM] Stable Channel Update for Desktop: CVE-2022-3308
Stable Channel Update for Desktop
CVE-2022-3308: Insufficient policy enforcement in Developer Tools. Reported by Andrea Cappa (zi0Black) @ Shielder on 2022-07-08 [$4000][ 1348415 ] Medium CVE-2022-3309: Use after free in Assistant
Reported by zh1x1an1221 of Ant Group Tianqiong Security Lab on 2022-07-29 [$1000][ 1240065 ] Medium CVE-2022-3310: Insufficient policy enforcement in Custom Tabs
Severity: medium
CISA
Microsoft Windows Kernel Privilege Escalation Vulnerability
cisa·2022-03-15·CVSS 7.8
CVE-2016-3309 [HIGH] CWE-264 Microsoft Windows Kernel Privilege Escalation Vulnerability
Vulnerability: Microsoft Windows Kernel Privilege Escalation Vulnerability
Affected: Microsoft Windows
A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-3309
Remediation Due Date: 2022-04-05
Debian
CVE-2022-3309: chromium - Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 ...
vendor_debian·2022·CVSS 6.5
CVE-2022-3309 [MEDIUM] CVE-2022-3309: chromium - Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 ...
Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 106.0.5249.61-1)
bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1)
forky: resolved (fixed in 106.0.5249.61-1)
sid: resolved (fixed in 106.0.5249.61-1)
trixie: resolved (fixed in 106.0.5249.61-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-01
Published