EUVD-2022-42504
Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 8 Sept 2022. Evidence sources: cisa_kev.
- ENISA score
- 9.6 · CVSS 3.1
- Advisory evidence
- 8 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_opensuse · openSUSE-SU-2022:10118-1Security update for opera
- csaf_opensuse · openSUSE-SU-2022:10120-1Security update for chromium
- csaf_opensuse · openSUSE-SU-2022:10117-1Security update for opera
- csaf_opensuse · openSUSE-SU-2022:10119-1Security update for chromium
- csaf_opensuse · openSUSE-SU-2022:10121-1Security update for opera
