CVE-2022-2480: Use after free in Service Worker API
Published Jun 27, 2022
·Updated
Use after free in Service Worker API in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Sergei Glazunov(Google Project Zero)
Affected Software
2 affected componentsFixes available
Google Chrome<103.0.5060.134
103.0.5060.134
Google Chrome<103.0.5060.134
Event History
Jun 27, 2022
CVE Published
12:00 AM
Jul 28, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-2480?
CVE-2022-2480 has been classified as a high-severity vulnerability.
2
How do I fix CVE-2022-2480?
To fix CVE-2022-2480, update Google Chrome to version 103.0.5060.134 or later.
3
What types of attacks can exploit CVE-2022-2480?
CVE-2022-2480 could potentially be exploited through crafted HTML pages leading to heap corruption.
4
Can CVE-2022-2480 affect all users of Google Chrome?
Yes, any user of Google Chrome versions prior to 103.0.5060.134 is at risk from CVE-2022-2480.
5
Is there a workaround for CVE-2022-2480?
There are no official workarounds for CVE-2022-2480; the most effective solution is to apply the update.