First published: Thu Jan 13 2022(Updated: )
Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and convinced a user to enage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
Credit: chrome-cve-admin@google.com Thomas Orlita
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <98.0.4758.102 | |
Google Chrome | <98.0.4758.102 | 98.0.4758.102 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-0605 is classified as a high severity vulnerability due to its potential for exploitation and impact on system security.
To fix CVE-2022-0605, users should update Google Chrome to version 98.0.4758.102 or later.
CVE-2022-0605 enables an attacker to exploit heap corruption through a malicious extension and specific user interactions.
Users of Google Chrome versions prior to 98.0.4758.102 are affected by CVE-2022-0605.
CVE-2022-0605 affects the Webstore API component in Google Chrome.