CVE-2022-0604 is a heap buffer overflow vulnerability affecting Google Chrome prior to version 98.0.4758.102, specifically within the Tab Groups feature. This high-severity vulnerability (CVSS 8.8) could allow an attacker to achieve heap corruption via a crafted HTML page, but requires the user to install a malicious extension and engage in specific interactions. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating notable attention from researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 98.0.4758.102CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.