CVE-2022-0790: Use after free in Cast UI
Published Nov 23, 2021
·Updated
Use after free in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially perform a sandbox escape via a crafted HTML page.
Credit
Anonymous
Affected Software
2 affected componentsFixes available
Google Chrome<99.0.4844.51
99.0.4844.51
Google Chrome<99.0.4844.51
Event History
Nov 23, 2021
CVE Published
12:00 AM
Apr 5, 2022
CVE Published
via MITRE·12:25 AM
Data Sourced
via MITRE·12:25 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-0790?
CVE-2022-0790 is considered a high severity vulnerability due to its potential for sandbox escape.
2
How do I fix CVE-2022-0790?
To mitigate CVE-2022-0790, users should update Google Chrome to version 99.0.4844.51 or later.
3
What type of vulnerability is CVE-2022-0790?
CVE-2022-0790 is classified as a 'use after free' vulnerability in the Cast UI of Google Chrome.
4
Can CVE-2022-0790 be exploited remotely?
Yes, CVE-2022-0790 can be exploited remotely if a user is tricked into interacting with a specially crafted HTML page.
5
Which versions of Google Chrome are affected by CVE-2022-0790?
CVE-2022-0790 affects all versions of Google Chrome prior to 99.0.4844.51.