CVE-2022-0458 is a use-after-free vulnerability in Google Chrome's Thumbnail Tab Strip, affecting versions prior to 98.0.4758.80. This flaw allows a remote attacker to potentially exploit heap corruption by enticing a user to visit a specially crafted HTML page. With a CVSS score of 8.8 (High), it presents a significant risk due to its network attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation (KEV: No) and no public exploit code available, the vulnerability has garnered notable community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 98.0.4758.80CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.