CVE-2022-1489: Out of bounds memory access in UI Shelf
Out of bounds memory access in UI Shelf in Google Chrome on Chrome OS, Lacros prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific user interactions.
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-1477
- CVE-2022-1478
- CVE-2022-1479
- CVE-2022-4920
- CVE-2022-1481
- CVE-2022-1919
- CVE-2022-4919
- CVE-2022-1482
- CVE-2022-1483
- CVE-2022-1484
- CVE-2022-1485
- CVE-2022-1486
- CVE-2022-1487
- CVE-2022-1488
- CVE-2022-1490
- CVE-2022-1491
- CVE-2022-1492
- CVE-2022-1493
- CVE-2022-1494
- CVE-2022-1495
- CVE-2022-1496
- CVE-2022-1497
- CVE-2022-1498
- CVE-2022-1499
- CVE-2022-1500
- CVE-2022-1501
Frequently Asked Questions
What is CVE-2022-1489?
CVE-2022-1489 is a vulnerability that allows a remote attacker to potentially exploit heap corruption in UI Shelf in Google Chrome on Chrome OS Lacros prior to 101.0.4951.41 via specific user interactions.
How severe is CVE-2022-1489?
CVE-2022-1489 has a severity rating of 8.8 (high).
How can a remote attacker exploit CVE-2022-1489?
A remote attacker can potentially exploit CVE-2022-1489 by performing specific user interactions that trigger out of bounds memory access in UI Shelf in Google Chrome on Chrome OS Lacros.
Is Google Chrome OS affected by CVE-2022-1489?
No, Google Chrome OS is not affected by CVE-2022-1489.
How do I fix CVE-2022-1489?
To fix CVE-2022-1489, you should update Google Chrome on Chrome OS Lacros to version 101.0.4951.41 or later.