SB2022092741 - Multiple vulnerabilities in Google Chrome
Published: September 27, 2022 Updated: August 16, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 19 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2022-3312)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied input in VPN in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
2) Use-after-free (CVE-ID: CVE-2022-3318)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to use-after-free error in ChromeOS Notifications in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.
3) Input validation error (CVE-ID: CVE-2022-3317)
The vulnerability allows a remote attacker to gain access to crash the browser.
The vulnerability exists due to a improper input validation in Intents in Google Chrome. A remote attacker can trick the victim to perform certain actions in browser and crash it.
4) Input validation error (CVE-ID: CVE-2022-3316)
The vulnerability allows a remote attacker to gain access to crash the browser.
The vulnerability exists due to a improper input validation in Safe Browsing in Google Chrome. A remote attacker can trick the victim to perform certain actions in browser and crash it.
5) Type Confusion (CVE-ID: CVE-2022-3315)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a type confusion error within the Blink component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a type confusion error and gain access to sensitive information.
6) Use-after-free (CVE-ID: CVE-2022-3314)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Logging in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
7) Spoofing attack (CVE-ID: CVE-2022-3313)
The vulnerability allows a remote attacker to perform a spoofing attack.
The vulnerability exists due to insufficient validation of user-supplied input in Full Screen in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and spoof web page content.
8) Use-after-free (CVE-ID: CVE-2022-3311)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Import in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
9) Use-after-free (CVE-ID: CVE-2022-3304)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the CSS component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
10) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2022-3310)
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient policy enforcement in Custom Tabs in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and gain access to sensitive information.
11) Use-after-free (CVE-ID: CVE-2022-3309)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Assistant in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
12) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2022-3308)
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient policy enforcement in Developer Tools in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and gain access to sensitive information.
13) Use-after-free (CVE-ID: CVE-2022-3307)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Media component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
14) Use-after-free (CVE-ID: CVE-2022-3306)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Survey component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
15) Use-after-free (CVE-ID: CVE-2022-3305)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Survey component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
16) Input validation error (CVE-ID: CVE-2022-3201)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation in DevTools component in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
17) Input validation error (CVE-ID: CVE-2022-3443)
The vulnerability allows a remote attacker to manipulate data on the system.
The vulnerability exists due to insufficient validation of user-supplied input in in File System API. A remote attacker can trick the victim to visit a specially crafted website and manipulate data on the system.
18) Input validation error (CVE-ID: CVE-2022-3444)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied input in File System API in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
19) Input validation error (CVE-ID: CVE-2022-4911)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied input in DevTools in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
Remediation
Install update from vendor's website.
References
- https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop_27.html
- https://crbug.com/1303306
- https://crbug.com/1318791
- https://crbug.com/1300539
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-3317
- https://crbug.com/1333623
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-3316
- https://crbug.com/1322812
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-3315
- https://crbug.com/1328708
- https://crbug.com/1317904
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-3313
- https://crbug.com/1302813
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-3311
- https://crbug.com/1358907
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-3304
- https://crbug.com/1240065
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-3310
- https://crbug.com/1348415
- https://crbug.com/1342722
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-3308
- https://crbug.com/1323488
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-3307
- https://crbug.com/1320139
- https://crbug.com/1319229
- https://crbug.com/1343104
- https://crbug.com/1243802
- https://crbug.com/1208439
- https://crbug.com/1349493