CVE-2022-0793
Gentoo Linux Security Advisory 202208-25
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Use after free in Cast in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension and engage in specific user interaction to potentially exploit heap corruption via a crafted Chrome Extension.
Un uso de memoria previamente liberada en Cast en Google Chrome versiones anteriores a 99.0.4844.51, permitía que un atacante que convenciera a un usuario de instalar una extensión maliciosa y participar en una interacción específica con el usuario explotar potencialmente una corrupción de la pila por medio de una extensión de Chrome diseñada
Multiple vulnerabilities have been found in Chromium and its derivatives, the worst of which could result in remote code execution. Versions less than 5.15.5_p20220618>= are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-01 CVE Reserved
- 2022-03-28 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-416: Use After Free
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://crbug.com/1291728 | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop.html | 2022-10-27 | |
https://security.gentoo.org/glsa/202208-25 | 2022-10-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | < 99.0.4844.51 Search vendor "Google" for product "Chrome" and version " < 99.0.4844.51" | - |
Affected
|