CVE-2022-0972: Use after free in Extensions
Use after free in Extensions in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-0972?
CVE-2022-0972 has a high severity rating due to its potential for heap corruption via malicious extensions in Google Chrome.
How do I fix CVE-2022-0972?
To fix CVE-2022-0972, update Google Chrome to version 99.0.4844.74 or later.
What could an attacker achieve by exploiting CVE-2022-0972?
An attacker could potentially exploit CVE-2022-0972 to execute arbitrary code by convincing users to install a malicious extension.
What versions of Google Chrome are affected by CVE-2022-0972?
CVE-2022-0972 affects versions of Google Chrome prior to 99.0.4844.74.
Is CVE-2022-0972 relevant for users on other operating systems?
CVE-2022-0972 specifically impacts users of Google Chrome on desktop environments, with no direct impact on mobile or embedded operating systems.