CVE-2022-1308PoC(google / chrome)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Use after free in BFCache in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
chrome

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-08: 1PoC Mentioned / Linked · 2026-03-08: 1Technical Details · 2026-03-08: 103-08
Signal classification1 categories
PoC
1100.0%
Full discourse1 post
  • りいんちゃん@reinforchu
    PoC

    タッチの差なので文句は言えんけど、CVE-2022-1308 (Google Chrome Heap User-After-Free Vulnerability)は何でもいいからPoCを先に出した方が勝ちゲームに負けて横取り(ひどい言い方)されたのを恨み節にずっと言ってる。Google VRPの報奨金は私が受け取ったけど。。。

    Post summary

    The user laments that someone else posted a PoC for CVE-2022-1308 before them and claims credit was taken, but there is no evidence of exploitation or mitigation.

    00000593
    4.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---

Explore more