CVE-2022-0289: Use after free in Safe browsing
Published Jan 5, 2022
·Updated
Use after free in Safe browsing in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Sergei Glazunov(Google Project Zero)
Affected Software
2 affected componentsFixes available
Google Chrome<97.0.4692.99
97.0.4692.99
Google Chrome<97.0.4692.99
Event History
Jan 5, 2022
CVE Published
12:00 AM
Feb 12, 2022
CVE Published
via MITRE·01:35 AM
Data Sourced
via MITRE·01:35 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-0289?
CVE-2022-0289 is classified as a high severity vulnerability that can lead to potential heap corruption.
2
How do I fix CVE-2022-0289?
To fix CVE-2022-0289, update Google Chrome to version 97.0.4692.99 or later.
3
What type of vulnerability is CVE-2022-0289?
CVE-2022-0289 is a use after free vulnerability specifically affecting the Safe Browsing feature in Google Chrome.
4
Who is affected by CVE-2022-0289?
Users of Google Chrome versions prior to 97.0.4692.99 are affected by CVE-2022-0289.
5
Can CVE-2022-0289 be exploited remotely?
Yes, CVE-2022-0289 can potentially be exploited remotely via a specially crafted HTML page.