Junglewise Threat Intelligence

CVE-2022-3038: Google Chromium Network Service Use-After-Free Vulnerability

CVE-2022-3038 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2023-03-30

Technologies: Google Chrome, Microsoft Edge. Vendors: Opera, Google, Microsoft.

Executive brief

A use-after-free vulnerability exists in the Network Service of Google Chromium. A remote attacker can exploit this via a specially crafted HTML page to cause heap corruption, potentially leading to arbitrary code execution.

Affected products

  • Google Chrome prior to 105.0.5195.52
  • Microsoft Edge
  • Opera Opera

Timeline

  • 2022-08-30: patched: Stable channel update for desktop released (105.0.5195.52)
  • 2023-03-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-03-30: disclosed: NVD publication date
  • 2023-03-30: exploited: Reported as exploited in the wild per CISA KEV and advisory metadata.