CVE-2022-0302 describes a use-after-free vulnerability in the Omnibox component of Google Chrome prior to version 97.0.4692.99. This flaw could allow an attacker to exploit heap corruption via a specially crafted HTML page, provided they could convince a user to perform specific interactions. Rated with a CVSS score of 8.8 (HIGH), this vulnerability has a network attack vector, low attack complexity, and could lead to high impacts on confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, it has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 97.0.4692.99CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.