CVE-2022-0606: Use after free in ANGLE
Published Jan 17, 2022
·Updated
Use after free in ANGLE in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Cassidy Kim(Amber Security Lab), OPPO Mobile Telecommunications Corp. Ltd.
Affected Software
2 affected componentsFixes available
Google Chrome<98.0.4758.102
98.0.4758.102
Google Chrome<98.0.4758.102
Event History
Jan 17, 2022
CVE Published
12:00 AM
Apr 4, 2022
CVE Published
via MITRE·11:55 PM
Data Sourced
via MITRE·11:55 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-0606?
CVE-2022-0606 is classified as a high severity vulnerability in Google Chrome.
2
What does CVE-2022-0606 exploit?
CVE-2022-0606 exploits a use after free vulnerability in ANGLE, allowing potential heap corruption.
3
How do I fix CVE-2022-0606?
To mitigate CVE-2022-0606, update Google Chrome to version 98.0.4758.102 or later.
4
Who is affected by CVE-2022-0606?
Users of Google Chrome prior to version 98.0.4758.102 are affected by CVE-2022-0606.
5
What type of attack can CVE-2022-0606 allow?
CVE-2022-0606 may allow a remote attacker to execute a crafted HTML page that could exploit the vulnerability.