CVE-2022-0791: Use after free in Omnibox
Published Dec 9, 2021
·Updated
Use after free in Omnibox in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via user interactions.
Credit
Zhihua Yao(KunLun Lab)
Affected Software
5 affected componentsFixes available
Google Chrome<99.0.4844.51
99.0.4844.51
Google Chrome<99.0.4844.51
Apple macOS
Linux Linux kernel
Microsoft Windows
Event History
Dec 9, 2021
CVE Published
12:00 AM
Apr 5, 2022
CVE Published
via MITRE·12:25 AM
Data Sourced
via MITRE·12:25 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-0791?
CVE-2022-0791 is classified as a high-severity vulnerability due to its potential for remote exploitation through user interaction.
2
How do I fix CVE-2022-0791?
To fix CVE-2022-0791, update Google Chrome to version 99.0.4844.51 or later.
3
What type of vulnerability is CVE-2022-0791?
CVE-2022-0791 is a use-after-free vulnerability affecting the Omnibox component in Google Chrome.
4
Who is affected by CVE-2022-0791?
Users of Google Chrome versions prior to 99.0.4844.51 are affected by CVE-2022-0791.
5
Can CVE-2022-0791 be exploited without user interaction?
No, CVE-2022-0791 requires specific user interactions to potentially exploit heap corruption.