CVE-2022-0796: Use after free in Media
Published Feb 10, 2022
·Updated
Use after free in Media in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Cassidy Kim(Amber Security Lab), OPPO Mobile Telecommunications Corp. Ltd.
Affected Software
5 affected componentsFixes available
Google Chrome<99.0.4844.51
99.0.4844.51
Google Chrome<99.0.4844.51
macOS
Linux Linux Kernel
Microsoft Windows
Event History
Feb 10, 2022
CVE Published
12:00 AM
Apr 5, 2022
CVE Published
via MITRE·12:25 AM
Data Sourced
via MITRE·12:25 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-0796?
CVE-2022-0796 is considered a high severity vulnerability due to its ability to cause heap corruption.
2
How do I fix CVE-2022-0796?
To fix CVE-2022-0796, upgrade Google Chrome to version 99.0.4844.51 or later.
3
What is affected by CVE-2022-0796?
CVE-2022-0796 affects Google Chrome versions prior to 99.0.4844.51.
4
Can CVE-2022-0796 be exploited remotely?
Yes, CVE-2022-0796 can be exploited remotely through a crafted HTML page.
5
What type of vulnerability is CVE-2022-0796?
CVE-2022-0796 is categorized as a use after free vulnerability in the Media component of Google Chrome.