CVE-2022-3075
Google Chromium Mojo Insufficient Data Validation Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 29 September 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- CVSS 3.1
- 9.6 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- EPSS
- 5.76% probability · 93th percentile
- CISA KEV
- Listed 8 September 2022 · due 29 September 2022
- Weakness
- CWE-20
- Affected
- google/chrome · fedoraproject/fedora
- Source
- chrome-cve-admin@google.com
CISA notes
Apply updates per vendor instructions. https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop.html, https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-3075; https://nvd.nist.gov/vuln/detail/CVE-2022-3075
References
- https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop.htmlRelease Notes, Vendor Advisory
- https://crbug.com/1358134Permissions Required
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE/Third Party Advisory
- https://security.gentoo.org/glsa/202209-23Third Party Advisory
- https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop.htmlRelease Notes, Vendor Advisory
- https://crbug.com/1358134Permissions Required
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE/Third Party Advisory
- https://security.gentoo.org/glsa/202209-23Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-3075US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.