CVE-2022-0607 is a use-after-free vulnerability in the GPU component of Google Chrome, affecting versions prior to 98.0.4758.102. This flaw allows a remote attacker to potentially exploit heap corruption by enticing a user to visit a specially crafted HTML page. It carries a high CVSS score of 8.8, indicating high impact on confidentiality, integrity, and availability, with low attack complexity. While not listed in CISA's KEV catalog, the vulnerability has garnered significant community discussion and media coverage, including reports of Google discovering an attack exploiting this zero-day.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 98.0.4758.102CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.