CVE-2022-0297: Use after free in Vulkan
Published Nov 28, 2021
·Updated
Use after free in Vulkan in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Cassidy Kim(Amber Security Lab), OPPO Mobile Telecommunications Corp. Ltd.
Affected Software
2 affected componentsFixes available
Google Chrome<97.0.4692.99
97.0.4692.99
Google Chrome<97.0.4692.99
Event History
Nov 28, 2021
CVE Published
12:00 AM
Feb 12, 2022
CVE Published
via MITRE·01:35 AM
Data Sourced
via MITRE·01:35 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-0297?
CVE-2022-0297 is classified as a high-severity vulnerability due to the potential for heap corruption leading to exploitation.
2
How do I fix CVE-2022-0297?
To fix CVE-2022-0297, update your Google Chrome browser to version 97.0.4692.99 or later.
3
What is the main risk associated with CVE-2022-0297?
The main risk associated with CVE-2022-0297 is the possibility of a remote attacker exploiting the vulnerability through a crafted HTML page.
4
Which versions of Google Chrome are affected by CVE-2022-0297?
Google Chrome versions prior to 97.0.4692.99 are affected by CVE-2022-0297.
5
Is there a workaround for CVE-2022-0297 if I cannot update?
There is no known workaround for CVE-2022-0297; updating to the latest version is the recommended solution.