CVE-2022-0456: Use after free in Web Search
Published Jan 21, 2022
·Updated
Use after free in Web Search in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via profile destruction.
Credit
Zhihua Yao(KunLun Lab)
Affected Software
2 affected componentsFixes available
Google Chrome<98.0.4758.80
98.0.4758.80
Google Chrome<98.0.4758.80
Event History
Jan 21, 2022
CVE Published
12:00 AM
Apr 5, 2022
CVE Published
via MITRE·12:51 AM
Data Sourced
via MITRE·12:51 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-0456?
CVE-2022-0456 is classified as a high-severity vulnerability due to its potential to allow remote code execution through heap corruption.
2
How do I fix CVE-2022-0456?
To fix CVE-2022-0456, users need to update Google Chrome to version 98.0.4758.80 or later.
3
What type of vulnerability is CVE-2022-0456?
CVE-2022-0456 is a use-after-free vulnerability affecting the Web Search feature in Google Chrome.
4
Who is affected by CVE-2022-0456?
CVE-2022-0456 affects all users of Google Chrome versions prior to 98.0.4758.80.
5
What can happen if CVE-2022-0456 is exploited?
If exploited, CVE-2022-0456 can lead to heap corruption, potentially enabling attackers to execute arbitrary code on affected systems.