Coming Soon...

Q-CERT website is currently under maintenance. We should be back shortly. Thank you for yor patience.

Multiple Vulnerabilities in Google Chrome

Issued: 
Thursday, 13 October, 2022
Last Revision: 
Thursday, 13 October, 2022
Vendor: 
Product: 
Severity Level: 
Summary: 

Google chrome web browser is affected by multiple vulnerabilities.

 

This update includes six security fixes. 

 

Stable channel has been updated to 106.0.5249.119 for Windows, Mac and Linux.

 

 

CVE/Vulnerability

Description 

Severity

Exploitable

 

 

CVE-2022-3445

Use after free in Skia.

High

No

 

 

CVE-2022-3446

Heap buffer overflow in WebSQL

High

No

 

 

CVE-2022-3447

Inappropriate implementation in Custom Tabs

High

No

 

 

CVE-2022-3448

Use after free in Permissions API

High

No

 

 

CVE-2022-3449

Use after free in Safe Browsing.

High

No

 

 

CVE-2022-3450

Use after free in Peer Connection

High

No

 

       

 

Table 1: Vulnerability details

 

 

CVE/Vulnerability

Affected Product(s)

 

 

CVE-2022-3445

CVE-2022-3446

CVE-2022-3447

CVE-2022-3448

CVE-2022-3449

CVE-2022-3450

Upgrade to Google Chrome version 106.0.5249.119 or later (Windows, MacOS,

Linux)

 

     

 

Table 2: Vulnerable versions

 

Recommendation: 

We recommend entities to follow the “Google Chrome recommendation, to update the latest version.