CVE-2022-1496: Use after free in File Manager
Published Mar 15, 2022
·Updated
Use after free in File Manager in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific and direct user interaction.
Credit
Zhiyi Zhang(Codesafe Team of Legendsec at Qi'anxin Group), Zhunki(Codesafe Team of Legendsec at Qi'anxin Group)
Affected Software
2 affected componentsFixes available
Google Chrome<101.0.4951.41
101.0.4951.41
Google Chrome<101.0.4951.41
Remediation
Patch Available
Event History
Mar 15, 2022
CVE Published
12:00 AM
Jul 26, 2022
CVE Published
via MITRE·09:34 PM
Data Sourced
via MITRE·09:34 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-1477
- CVE-2022-1478
- CVE-2022-1479
- CVE-2022-4920
- CVE-2022-1481
- CVE-2022-1919
- CVE-2022-4919
- CVE-2022-1482
- CVE-2022-1483
- CVE-2022-1484
- CVE-2022-1485
- CVE-2022-1486
- CVE-2022-1487
- CVE-2022-1488
- CVE-2022-1489
- CVE-2022-1490
- CVE-2022-1491
- CVE-2022-1492
- CVE-2022-1493
- CVE-2022-1494
- CVE-2022-1495
- CVE-2022-1497
- CVE-2022-1498
- CVE-2022-1499
- CVE-2022-1500
- CVE-2022-1501
Frequently Asked Questions
1
What is the severity of CVE-2022-1496?
CVE-2022-1496 is classified as a high severity vulnerability due to its potential for exploitation through heap corruption.
2
How do I fix CVE-2022-1496?
To fix CVE-2022-1496, update Google Chrome to version 101.0.4951.41 or later.
3
What type of vulnerability is CVE-2022-1496?
CVE-2022-1496 is a use after free vulnerability found in the File Manager component of Google Chrome.
4
What can an attacker do with CVE-2022-1496?
An attacker can potentially exploit CVE-2022-1496 to cause heap corruption through specific user interactions.
5
Which versions of Google Chrome are affected by CVE-2022-1496?
CVE-2022-1496 affects Google Chrome versions prior to 101.0.4951.41.