8.8
CVSSv3

CVE-2022-0605

Published: 05/04/2022 Updated: 11/04/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Use after free in Webstore API in Google Chrome before 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and convinced a user to enage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

Vendor Advisories

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure For the stable distribution (bullseye), these problems have been fixed in version 9804758102-1~deb11u1 We recommend that you upgrade your chromium packages For the detailed security status of ...
The Stable channel has been updated to 9804758102 for Windows, Mac and Linux which will roll out over the coming days/weeks Extended stable channel has also been updated to 9804758102 for Windows and Mac which will roll out over the coming days/weeksA full list of changes in this build is available in the log Interested in switching release ...
LTS-96 has been updated in the LTS channel to 9604664202 (Platform Version: 14268770) for most ChromeOS devices Want to know more about Long-term Support? Click here This update includes the following Security fixes:1295786  High  CVE-2022-0796 uaf in blink::MediaInspectorContextImpl::CullPlayers(blink::Web ...

Github Repositories

Exploitable KB Finder 🧐 It was written to check whether KB vulnerabilities in Nessus outputs are exploitable It finds which CVEs are covered by the KB update you provide as input and searches the 'exploitable', 'publicly disclosed' properties of these CVEs You can directly search for CVE/CVE's from MSRC database too (-cve/-cve_list) option Usage

Recent Articles

IT threat evolution in Q1 2022. Non-mobile statistics
Securelist • AMR • 27 May 2022

IT threat evolution in Q1 2022 IT threat evolution in Q1 2022. Non-mobile statistics IT threat evolution in Q1 2022. Mobile statistics These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data. Quarterly figures According to Kaspersky Security Network, in Q1 2022: Kaspersky solutions blocked 1,216,350,437 attacks from online resources across the globe. Web Anti-Virus recognized 313,164,030 unique URLs as ma...