CVE-2022-0463: Use after free in Accessibility
Published Nov 9, 2021
·Updated
Use after free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.
Credit
Zhihua Yao(KunLun Lab)
Affected Software
2 affected componentsFixes available
Google Chrome<98.0.4758.80
98.0.4758.80
Google Chrome<98.0.4758.80
Event History
Nov 9, 2021
CVE Published
12:00 AM
Apr 5, 2022
CVE Published
via MITRE·12:51 AM
Data Sourced
via MITRE·12:51 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-0463?
CVE-2022-0463 is categorized as a high severity vulnerability due to the potential for heap corruption.
2
How do I fix CVE-2022-0463?
To fix CVE-2022-0463, update Google Chrome to version 98.0.4758.80 or later.
3
What type of vulnerability is CVE-2022-0463?
CVE-2022-0463 is a use after free vulnerability in the Accessibility component of Google Chrome.
4
Who is affected by CVE-2022-0463?
Users of Google Chrome versions prior to 98.0.4758.80 are affected by CVE-2022-0463.
5
Can CVE-2022-0463 be exploited remotely?
Yes, CVE-2022-0463 can potentially be exploited remotely through specific user interactions.