CVE-2022-0978: Use after free in ANGLE
Published Feb 20, 2022
·Updated
Use after free in ANGLE in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Cassidy Kim(Amber Security Lab), OPPO Mobile Telecommunications Corp. Ltd.
Affected Software
2 affected componentsFixes available
Google Chrome<99.0.4844.74
99.0.4844.74
Google Chrome<99.0.4844.74
Remediation
Patch Available
Event History
Feb 20, 2022
CVE Published
12:00 AM
Jul 21, 2022
CVE Published
via MITRE·09:06 PM
Data Sourced
via MITRE·09:06 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-0978?
CVE-2022-0978 has a high severity rating due to its potential to allow remote attackers to exploit heap corruption.
2
How do I fix CVE-2022-0978?
To fix CVE-2022-0978, update Google Chrome to version 99.0.4844.74 or later.
3
What impact does CVE-2022-0978 have on users?
CVE-2022-0978 may lead to unwanted behavior in Chrome, potentially allowing an attacker to execute arbitrary code.
4
How can I determine if I am vulnerable to CVE-2022-0978?
You are vulnerable to CVE-2022-0978 if your Google Chrome version is prior to 99.0.4844.74.
5
What causes the vulnerability in CVE-2022-0978?
CVE-2022-0978 is caused by a use after free flaw in the ANGLE component of Google Chrome.