CVE-2022-0974: Use after free in Splitscreen
Published Jan 28, 2022
·Updated
Use after free in Splitscreen in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
Credit
@@ginggilBesel
Affected Software
2 affected componentsFixes available
Google Chrome<99.0.4844.74
99.0.4844.74
Google Chrome<99.0.4844.74
Remediation
Patch Available
Event History
Jan 28, 2022
CVE Published
12:00 AM
Jul 21, 2022
CVE Published
via MITRE·09:05 PM
Data Sourced
via MITRE·09:05 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-0974?
CVE-2022-0974 has a high severity rating due to the potential for heap corruption and exploitation by remote attackers.
2
How do I fix CVE-2022-0974?
To fix CVE-2022-0974, update Google Chrome to version 99.0.4844.74 or later.
3
What causes CVE-2022-0974?
CVE-2022-0974 is caused by a use after free vulnerability in the Splitscreen feature of Google Chrome.
4
How can CVE-2022-0974 be exploited?
CVE-2022-0974 can be exploited by convincing a user to interact with a specially crafted HTML page.
5
Which versions of Google Chrome are affected by CVE-2022-0974?
Google Chrome versions prior to 99.0.4844.74 are affected by CVE-2022-0974.