CVE-2022-0290: Use after free in Site isolation
Use after free in Site isolation in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-0290?
The severity of CVE-2022-0290 is critical with a CVSS score of 9.6.
What is CVE-2022-0290?
CVE-2022-0290 is a vulnerability in Site isolation in Google Chrome prior to version 97.0.4692.99 that allowed a remote attacker to potentially perform a sandbox escape.
What is the affected software for CVE-2022-0290?
The affected software for CVE-2022-0290 is Google Chrome versions prior to 97.0.4692.99.
How can I fix CVE-2022-0290?
To fix CVE-2022-0290, it is recommended to update Google Chrome to version 97.0.4692.99 or later.
Are there any references for CVE-2022-0290?
Yes, you can find references for CVE-2022-0290 at the following links: [http://packetstormsecurity.com/files/166080/Chrome-RenderFrameHostImpl-Use-After-Free.html](http://packetstormsecurity.com/files/166080/Chrome-RenderFrameHostImpl-Use-After-Free.html), [https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop_19.html](https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop_19.html), [https://crbug.com/1260134](https://crbug.com/1260134).