CVE-2022-2399: Use after free in WebGPU
Published Apr 4, 2022
·Updated
Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Piotr Bania(Cisco Talos)
Affected Software
2 affected componentsFixes available
Google Chrome<100.0.4896.88
100.0.4896.88
Google Chrome<100.0.4896.88
Remediation
Patch Available
Event History
Apr 4, 2022
CVE Published
12:00 AM
Jul 28, 2022
CVE Published
via MITRE·09:35 PM
Data Sourced
via MITRE·09:35 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-2399?
CVE-2022-2399 has a severity rating of high due to potential heap corruption vulnerabilities.
2
How do I fix CVE-2022-2399?
To fix CVE-2022-2399, update Google Chrome to version 100.0.4896.88 or later.
3
What is the cause of CVE-2022-2399?
CVE-2022-2399 is caused by a use after free vulnerability in the WebGPU implementation in Google Chrome.
4
Can CVE-2022-2399 be exploited remotely?
Yes, CVE-2022-2399 can potentially be exploited remotely via a crafted HTML page.
5
Which versions of Google Chrome are affected by CVE-2022-2399?
CVE-2022-2399 affects all versions of Google Chrome prior to 100.0.4896.88.