CVE-2022-0605
published 2022-04-05CVE-2022-0605: Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and convinced…
PriorityP342high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.58%
44.3th percentile
Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and convinced a user to enage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 98.0.4758.102-1~deb11u1 | 98.0.4758.102-1~deb11u1 |
| chromium | chromium | >= 0 < 98.0.4758.102-1 | 98.0.4758.102-1 |
| chromium | chromium | >= 0 < 98.0.4758.102-1 | 98.0.4758.102-1 |
| chromium | chromium | >= 0 < 98.0.4758.102-1 | 98.0.4758.102-1 |
| debian | chromium | < chromium 98.0.4758.102-1 (bookworm) | chromium 98.0.4758.102-1 (bookworm) |
| chrome | < 98.0.4758.102 | 98.0.4758.102 | |
| chrome | >= unspecified < 98.0.4758.102 | 98.0.4758.102 | |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2hfr-4cgx-vgjv: Use after free in Webstore API in Google Chrome prior to 98
ghsa_unreviewed·2022-04-06
CVE-2022-0605 [HIGH] CWE-416 GHSA-2hfr-4cgx-vgjv: Use after free in Webstore API in Google Chrome prior to 98
Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and convinced a user to enage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
OSV
CVE-2022-0605: Use after free in Webstore API in Google Chrome prior to 98
osv·2022-04-05·CVSS 8.8
CVE-2022-0605 [HIGH] CVE-2022-0605: Use after free in Webstore API in Google Chrome prior to 98
Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and convinced a user to enage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
Microsoft
Chromium: CVE-2022-0605 Use after free in Webstore API
vendor_msrc·2022-02-08·CVSS 8.8
CVE-2022-0605 [HIGH] Chromium: CVE-2022-0605 Use after free in Webstore API
Chromium: CVE-2022-0605 Use after free in Webstore API
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
98.0.1108.55
2/15/2022
98.0.4758.102
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
I
Debian
CVE-2022-0605: chromium - Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed a...
vendor_debian·2022·CVSS 8.8
CVE-2022-0605 [HIGH] CVE-2022-0605: chromium - Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed a...
Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and convinced a user to enage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 98.0.4758.102-1)
bullseye: resolved (fixed in 98.0.4758.102-1~deb11u1)
forky: resolved (fixed in 98.0.4758.102-1)
sid: resolved (fixed in 98.0.4758.102-1)
trixie: resolved (fixed in 98.0.4758.102-1)
No detection rules found.
No public exploits indexed.
Securelist
IT threat evolution in Q1 2022. Non-mobile statistics
blogs_securelist·2022-05-27
IT threat evolution in Q1 2022. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Geography of financial malware attacks
TOP 10 banking malware families
Ransomware programs
Quarterly trends and highlights
Law enforcement successes
HermeticWiper, HermeticRansom and RUransom, etc.
Conti source-code leak
Attacks on NAS devices
Maze Decryptor
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by criminals during cyberattacks
Quarter highlights
Vulnerability statistics
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat
Securelist
PC malware statistics, Q1 2022
blogs_securelist·2022-05-27
PC malware statistics, Q1 2022
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by criminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q1 2022
- IT threat evolution in Q1 2022. Non-mobile statistics
- IT threat evolution in Q1 2022. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q1 2022:
- Kaspersky solutions blocked 1,216,350,437 attacks from online resources across the globe.
- Web Anti-Virus recognized 313,164,030 unique URLs as malicious.
- Attempts to run malware
2022-04-05
Published