CVE-2022-0302: Use after free in Omnibox
Published Dec 10, 2021
·Updated
Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed an attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page.
Credit
Weipeng Jiang@@Krace(360 Vulnerability Research Institute), Guang Gong(360 Vulnerability Research Institute)
Affected Software
2 affected componentsFixes available
Google Chrome<97.0.4692.99
97.0.4692.99
Google Chrome<97.0.4692.99
Event History
Dec 10, 2021
CVE Published
12:00 AM
Feb 12, 2022
CVE Published
via MITRE·01:35 AM
Data Sourced
via MITRE·01:35 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-0302?
CVE-2022-0302 is categorized as a high-severity vulnerability due to its potential for heap corruption.
2
How do I fix CVE-2022-0302?
To fix CVE-2022-0302, users should update Google Chrome to version 97.0.4692.99 or later.
3
What type of vulnerability is CVE-2022-0302?
CVE-2022-0302 is a use-after-free vulnerability found in the Omnibox of Google Chrome.
4
What could an attacker achieve by exploiting CVE-2022-0302?
An attacker could potentially exploit CVE-2022-0302 to perform heap corruption through a specially crafted HTML page.
5
In which versions of Google Chrome is CVE-2022-0302 present?
CVE-2022-0302 affects Google Chrome versions prior to 97.0.4692.99.