Junglewise Threat Intelligence

CVE-2022-3075: Google Chromium Mojo Insufficient Data Validation Vulnerability

CVE-2022-3075 · Severity: critical · CVSS 9.6 · Exploited in the wild · Published 2022-09-08

Technologies: Google Chrome, Microsoft Edge, Opera Software Opera. Vendors: Google, Microsoft, Opera Software.

Executive brief

Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker who has already compromised the renderer process to perform a sandbox escape. Exploitation is achieved via a crafted HTML page and affects multiple Chromium-based browsers.

Affected products

  • Google Chrome prior to 105.0.5195.102
  • Microsoft Edge
  • Opera Software Opera

Timeline

  • 2022-09-08: disclosed
  • 2022-09-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-09-02: patched: Chrome Stable Channel Update 105.0.5195.102 released to address this issue.
  • 2022-09-08: exploited: Google is aware of reports that an exploit for CVE-2022-3075 exists in the wild.

Related threats