CVE-2022-0793 is a use-after-free vulnerability in the Cast component of Google Chrome, affecting versions prior to 99.0.4844.51. It carries a high CVSS score of 8.8, indicating a critical risk where an attacker could achieve heap corruption and potentially full compromise if a user installs a malicious extension and performs specific interactions. There is no evidence of active exploitation, nor are there public exploit modules available in Metasploit or ExploitDB. Community discussion and media coverage are minimal, with only one mention and one article referencing it as part of a larger patch Tuesday update.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 99.0.4844.51CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.