CVE-2022-3075

CVE Published 2022-09-26
Related CWE(s) CWE-20: Improper Input Validation
Related Vendor(s) fedoraproject, google
Related Product(s) fedora, chrome
Exploitation Reported (CISA KEV) 2022-09-08
CVSS 3 Base Score 9.6 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References