Executive brief
Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker who has already compromised the renderer process to perform a sandbox escape. Exploitation is achieved via a crafted HTML page and affects multiple Chromium-based browsers.
Affected products
- Google Chrome prior to 105.0.5195.102
- Microsoft Edge
- Opera Software Opera
Timeline
- 2022-09-08: disclosed
- 2022-09-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-09-02: patched: Chrome Stable Channel Update 105.0.5195.102 released to address this issue.
- 2022-09-08: exploited: Google is aware of reports that an exploit for CVE-2022-3075 exists in the wild.