CVE-2022-0791 is a use-after-free vulnerability in the Omnibox component of Google Chrome versions prior to 99.0.4844.51, affecting Google, Apple, Linux, and Microsoft platforms. This high-severity flaw (CVSS 8.8) allows a remote attacker to potentially exploit heap corruption, leading to high impact on confidentiality, integrity, and availability, if a user is convinced to engage in specific interactions. While no public exploit code or active exploitation is reported, the vulnerability has garnered some community discussion and media coverage, including its mention in Microsoft's March 2022 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 99.0.4844.51CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.