PT-2022-1798 · Google+2 · Google Chrome+2

Published

2022-01-04

·

Updated

2024-06-15

·

CVE-2022-0107

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 97.0.4692.71
Description The issue is related to a use after free vulnerability in the File Manager API of Google Chrome, which can be exploited by an attacker using a specially crafted HTML page. This could potentially allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. The exploitation may involve convincing a user to install a malicious extension, which could then exploit heap corruption.
Recommendations For versions prior to 97.0.4692.71, update to version 97.0.4692.71 or later to resolve the issue. As a temporary workaround, consider restricting the installation of extensions to minimize the risk of exploitation. Avoid using the File Manager API in Google Chrome until the issue is resolved.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1008
ALT-PU-2022-1077
ALT-PU-2022-1136
ALT-PU-2022-1165
ALT-PU-2022-1290
BDU:2022-01198
CVE-2022-0107
DSA-5046-1
MGASA-2022-0043
OPENSUSE-SU-2022:0014-1
OPENSUSE-SU-2022:0047-1
OPENSUSE-SU-2022:0110-1
OPENSUSE-SU-2022_0047-1
OPENSUSE-SU-2022_0110-1
OPENSUSE-SU-2024:11739-1
OPENSUSE-SU-2024:12948-1

Affected Products

Alt Linux
Google Chrome
Suse