CVE-2022-0459 is a use-after-free vulnerability in the Screen Capture component of Google Chrome prior to version 98.0.4758.80. This flaw allows a remote attacker, who has compromised the renderer process and convinced a user to perform specific interactions, to potentially achieve heap corruption via a specially crafted HTML page. With a CVSS score of 8.8 (HIGH), this vulnerability has a network attack vector, low attack complexity, and requires user interaction, but could lead to high impacts on confidentiality, integrity, and availability. There is no evidence of active exploitation, nor are there publicly available exploits in Metasploit, Nuclei, or ExploitDB, despite some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 98.0.4758.80CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.