PT-2022-1538 · Google+3 · Google Chrome+3

Adam Weidemann

+1

·

Published

2022-02-14

·

Updated

2025-12-11

·

CVE-2022-0609

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 98.0.4758.102
Description The issue is related to a use-after-free vulnerability in the Animation component of Google Chrome. This vulnerability allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. The vulnerability could lead to the execution of arbitrary code on affected systems and damage to data. At least two distinct groups of North Korean state-sponsored hackers exploited this vulnerability to launch cyberattacks on the fintech, IT, and media industries.
Recommendations For Google Chrome versions prior to 98.0.4758.102, update to version 98.0.4758.102 or later to resolve the issue. As a temporary workaround, consider restricting access to the Animation component until a patch is applied. Avoid using the vulnerable API Web Animations until the issue is resolved.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1310
ALT-PU-2022-1323
ALT-PU-2022-1681
ALT-PU-2022-2055
BDU:2022-00743
CVE-2022-0609
DSA-5079-1
GHSA-VV6J-WW6X-54GX
OPENSUSE-SU-2022:0042-1
OPENSUSE-SU-2022:0077-1
OPENSUSE-SU-2022:0110-1
OPENSUSE-SU-2022_0077-1
OPENSUSE-SU-2022_0110-1
OPENSUSE-SU-2024:11849-1
OPENSUSE-SU-2024:11985-1
OPENSUSE-SU-2024:12948-1

Affected Products

Alt Linux
Astra Linux
Google Chrome
Suse