CVE-2022-0797 is an out-of-bounds memory write vulnerability in Google Chrome's Mojo component, affecting versions prior to 99.0.4844.51 across Apple, Google, Linux, and Microsoft platforms. This high-severity flaw (CVSS 8.8) can be exploited remotely with low complexity via a crafted HTML page, potentially leading to high impact on confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog or having public exploit code, it received some media coverage and community discussion, indicating awareness of the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 99.0.4844.51CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.