CVE-2022-3661
published 2022-11-01CVE-2022-3661: Insufficient data validation in Extensions in Google Chrome prior to 107.0.5304.62 allowed a remote attacker who had compromised the renderer process to leak…
PriorityP419medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.49%
39.6th percentile
Insufficient data validation in Extensions in Google Chrome prior to 107.0.5304.62 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted Chrome extension. (Chromium security severity: Low)
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 107.0.5304.68-1~deb11u1 | 107.0.5304.68-1~deb11u1 |
| chromium | chromium | >= 0 < 107.0.5304.68-1 | 107.0.5304.68-1 |
| chromium | chromium | >= 0 < 107.0.5304.68-1 | 107.0.5304.68-1 |
| chromium | chromium | >= 0 < 107.0.5304.68-1 | 107.0.5304.68-1 |
| debian | chromium | < chromium 107.0.5304.68-1 (bookworm) | chromium 107.0.5304.68-1 (bookworm) |
| chrome | < 107.0.5304.62 | 107.0.5304.62 | |
| chrome | >= unspecified < 107.0.5304.62 | 107.0.5304.62 | |
| chrome_chrome | — | — | |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
osv4.3MEDIUM
vendor_redhat7.8HIGH
vendor_debian4.3MEDIUM
vendor_msrc4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome Extensions input validation (EUVD-2022-43020)
vuldb·2026-07-19·CVSS 4.3
CVE-2022-3661 [MEDIUM] Google Chrome Extensions input validation (EUVD-2022-43020)
A vulnerability was found in Google Chrome. It has been rated as critical. The affected element is an unknown function of the component Extensions. This manipulation causes improper input validation.
This vulnerability is tracked as CVE-2022-3661. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
GHSA
GHSA-8jmr-7phq-hgh7: Insufficient data validation in Extensions in Google Chrome prior to 107
ghsa_unreviewed·2022-11-02
CVE-2022-3661 [MEDIUM] CWE-20 GHSA-8jmr-7phq-hgh7: Insufficient data validation in Extensions in Google Chrome prior to 107
Insufficient data validation in Extensions in Google Chrome prior to 107.0.5304.62 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted Chrome Extension. (Chrome security severity: Low)
OSV
CVE-2022-3661: Insufficient data validation in Extensions in Google Chrome prior to 107
osv·2022-11-01·CVSS 4.3
CVE-2022-3661 [MEDIUM] CVE-2022-3661: Insufficient data validation in Extensions in Google Chrome prior to 107
Insufficient data validation in Extensions in Google Chrome prior to 107.0.5304.62 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted Chrome extension. (Chromium security severity: Low)
Red Hat
kernel: jfs: fix invalid free of JFS_IP(ipimap)->i_imap in diUnmount
vendor_redhat·2025-10-04·CVSS 7.8
CVE-2023-53616 [HIGH] CWE-1341 kernel: jfs: fix invalid free of JFS_IP(ipimap)->i_imap in diUnmount
kernel: jfs: fix invalid free of JFS_IP(ipimap)->i_imap in diUnmount
In the Linux kernel, the following vulnerability has been resolved:
jfs: fix invalid free of JFS_IP(ipimap)->i_imap in diUnmount
syzbot found an invalid-free in diUnmount:
BUG: KASAN: double-free in slab_free mm/slub.c:3661 [inline]
BUG: KASAN: double-free in __kmem_cache_free+0x71/0x110 mm/slub.c:3674
Free of addr ffff88806f410000 by task syz-executor131/3632
CPU: 0 PID: 3632 Comm: syz-executor131 Not tainted 6.1.0-rc7-syzkaller-00012-gca57f02295f1 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/26/2022
Call Trace:
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x1b1/0x28e lib/dump_stack.c:106
print_address_description+0x74/0x340 mm/kasan/report.c:284
print_report+0x107/0x
Chrome
Stable Channel Update for Desktop: CVE-2022-4908
vendor_chrome·2022-10-25·CVSS 4.3
CVE-2022-4908 [MEDIUM] Stable Channel Update for Desktop: CVE-2022-4908
Stable Channel Update for Desktop
CVE-2022-4908: Inappropriate implementation in iFrame Sandbox. Reported by Johan Carlsson @joaxcar on 2022-09-02 [$3000][ 1350111 ] Low CVE-2022-3661: Insufficient data validation in Extensions
Reported by Young Min Kim (@ylemkimon), CompSec Lab at Seoul National University on 2022-08-04 [ $1000][ 1356211 ] Low CVE-2022-4909: Inappropriate implementation in XML
Severity: medium
Microsoft
Chromium: CVE-2022-3661 Insufficient data validation in Extensions
vendor_msrc·2022-10-11·CVSS 4.3
CVE-2022-3661 [MEDIUM] Chromium: CVE-2022-3661 Insufficient data validation in Extensions
Chromium: CVE-2022-3661 Insufficient data validation in Extensions
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsof
Debian
CVE-2022-3661: chromium - Insufficient data validation in Extensions in Google Chrome prior to 107.0.5304....
vendor_debian·2022·CVSS 4.3
CVE-2022-3661 [MEDIUM] CVE-2022-3661: chromium - Insufficient data validation in Extensions in Google Chrome prior to 107.0.5304....
Insufficient data validation in Extensions in Google Chrome prior to 107.0.5304.62 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted Chrome extension. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 107.0.5304.68-1)
bullseye: resolved (fixed in 107.0.5304.68-1~deb11u1)
forky: resolved (fixed in 107.0.5304.68-1)
sid: resolved (fixed in 107.0.5304.68-1)
trixie: resolved (fixed in 107.0.5304.68-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-01
Published