CVE-2022-0979Use After Free in Google Chrome

Severity
8.8HIGHNVD
EPSS
0.7%
top 28.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 22
Latest updateJul 23

Description

Use after free in Safe Browsing in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages7 packages

CVEListV5google/chromeunspecified99.0.4844.74
NVDgoogle/chrome< 99.0.4844.74
Gogogs.io/gogs< 0.12.8
debiandebian/chromium< chromium 99.0.4844.74-1 (bookworm)

Patches

🔴Vulnerability Details

3
GHSA
GHSA-h8vc-j6q3-h3ww: Use after free in Safe Browsing in Google Chrome on Android prior to 992022-07-23
OSV
CVE-2022-0979: Use after free in Safe Browsing in Google Chrome on Android prior to 992022-07-22
GHSA
OS Command Injection in gogs2022-06-02

📋Vendor Advisories

3
Chrome
Stable Channel Update for Desktop: CVE-2022-09792022-03-15
Microsoft
Chromium: CVE-2022-0979 Use after free in Safe Browsing2022-03-08
Debian
CVE-2022-0979: chromium - Use after free in Safe Browsing in Google Chrome on Android prior to 99.0.4844.7...2022