PT-2022-3955 · Google+2 · Google Chrome+2

·

CVE-2022-2415

·

Published

2022-04-14

·

Updated

2023-03-18

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 103.0.5060.53
Description The issue is related to a heap buffer overflow in the WebGL component of Google Chrome, which could be exploited by a remote attacker via a crafted HTML page, potentially leading to heap corruption. This could result in a denial of service or allow the execution of arbitrary code.
Recommendations For versions prior to 103.0.5060.53, update to version 103.0.5060.53 or later to resolve the issue. As a temporary workaround, consider restricting access to WebGL functionality until the update is applied.

Exploit

Fix

Memory Corruption

Heap Based Buffer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2141
ALT-PU-2022-2325
ALT-PU-2022-2835
ALT-PU-2023-1462
BDU:2022-04787
CVE-2022-2415
DSA-5168-1

Affected Products

Alt Linux
Astra Linux
Google Chrome