CVE-2022-0980: Use after free in New Tab Page
Published Mar 2, 2022
·Updated
Use after free in New Tab Page in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific user interactions.
Credit
Krace
Affected Software
2 affected componentsFixes available
Google Chrome<99.0.4844.74
99.0.4844.74
Google Chrome<99.0.4844.74
Remediation
Patch Available
Event History
Mar 2, 2022
CVE Published
12:00 AM
Jul 21, 2022
CVE Published
via MITRE·09:06 PM
Data Sourced
via MITRE·09:06 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-0980?
CVE-2022-0980 has been rated as high severity due to the potential for an attacker to exploit heap corruption.
2
How do I fix CVE-2022-0980?
To fix CVE-2022-0980, update Google Chrome to version 99.0.4844.74 or later.
3
What type of vulnerability is CVE-2022-0980?
CVE-2022-0980 is a use-after-free vulnerability that affects the New Tab Page in Google Chrome.
4
Who is affected by CVE-2022-0980?
Users of Google Chrome versions prior to 99.0.4844.74 are affected by CVE-2022-0980.
5
What could an attacker gain by exploiting CVE-2022-0980?
An attacker could potentially exploit CVE-2022-0980 to perform malicious actions such as executing arbitrary code.