CVE-2022-3659
published 2022-11-01CVE-2022-3659: Use after free in Accessibility in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed a remote attacker who convinced a user to engage in specific UI…
PriorityP344high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.54%
42.3th percentile
Use after free in Accessibility in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security severity: Medium)
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 107.0.5304.68-1~deb11u1 | 107.0.5304.68-1~deb11u1 |
| chromium | chromium | >= 0 < 107.0.5304.68-1 | 107.0.5304.68-1 |
| chromium | chromium | >= 0 < 107.0.5304.68-1 | 107.0.5304.68-1 |
| chromium | chromium | >= 0 < 107.0.5304.68-1 | 107.0.5304.68-1 |
| debian | chromium | < chromium 107.0.5304.68-1 (bookworm) | chromium 107.0.5304.68-1 (bookworm) |
| chrome | < 107.0.5304.62 | 107.0.5304.62 | |
| chrome | >= unspecified < 107.0.5304.62 | 107.0.5304.62 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome Accessibility use after free (EUVD-2022-43018)
vuldb·2026-07-19·CVSS 8.8
CVE-2022-3659 [HIGH] Google Chrome Accessibility use after free (EUVD-2022-43018)
A vulnerability was found in Google Chrome. It has been classified as critical. This issue affects some unknown processing of the component Accessibility. The manipulation leads to use after free.
This vulnerability is referenced as CVE-2022-3659. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
GHSA
GHSA-rq3j-7w29-7pqx: Use after free in Accessibility in Google Chrome on Chrome OS prior to 107
ghsa_unreviewed·2022-11-02
CVE-2022-3659 [HIGH] CWE-416 GHSA-rq3j-7w29-7pqx: Use after free in Accessibility in Google Chrome on Chrome OS prior to 107
Use after free in Accessibility in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chrome security severity: Medium)
OSV
CVE-2022-3659: Use after free in Accessibility in Google Chrome on Chrome OS prior to 107
osv·2022-11-01·CVSS 8.8
CVE-2022-3659 [HIGH] CVE-2022-3659: Use after free in Accessibility in Google Chrome on Chrome OS prior to 107
Use after free in Accessibility in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security severity: Medium)
Debian
CVE-2022-3659: chromium - Use after free in Accessibility in Google Chrome on Chrome OS prior to 107.0.530...
vendor_debian·2022·CVSS 8.8
CVE-2022-3659 [HIGH] CVE-2022-3659: chromium - Use after free in Accessibility in Google Chrome on Chrome OS prior to 107.0.530...
Use after free in Accessibility in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 107.0.5304.68-1)
bullseye: resolved (fixed in 107.0.5304.68-1~deb11u1)
forky: resolved (fixed in 107.0.5304.68-1)
sid: resolved (fixed in 107.0.5304.68-1)
trixie: resolved (fixed in 107.0.5304.68-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-01
Published