CVE-2022-0304: Use after free in Bookmarks
Published Dec 22, 2021
·Updated
Use after free in Bookmarks in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page.
Credit
Rong Jian(360 Alpha Lab), Guang Gong(360 Alpha Lab)
Affected Software
2 affected componentsFixes available
Google Chrome<97.0.4692.99
97.0.4692.99
Google Chrome<97.0.4692.99
Event History
Dec 22, 2021
CVE Published
12:00 AM
Feb 12, 2022
CVE Published
via MITRE·01:35 AM
Data Sourced
via MITRE·01:35 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-0304?
CVE-2022-0304 has a medium severity rating due to its potential for remote exploitation.
2
How do I fix CVE-2022-0304?
To fix CVE-2022-0304, update Google Chrome to version 97.0.4692.99 or later.
3
What is the impact of CVE-2022-0304?
CVE-2022-0304 may allow attackers to exploit heap corruption through a specially crafted HTML page.
4
Which versions of Google Chrome are affected by CVE-2022-0304?
CVE-2022-0304 affects all versions of Google Chrome prior to 97.0.4692.99.
5
Who discovered CVE-2022-0304?
CVE-2022-0304 was reported by external researchers contributing to the security of Google Chrome.