Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_29.html | release notes vendor advisory |
https://crbug.com/1303613 | issue tracking third party advisory |
https://security.gentoo.org/glsa/202208-25 | third party advisory vendor advisory |