CVE-2022-0798 is a use-after-free vulnerability in Google Chrome's MediaStream component, affecting versions prior to 99.0.4844.51 across Apple, Google, Linux, and Microsoft platforms. This high-severity flaw (CVSS 8.8) allows an unauthenticated attacker to achieve heap corruption and potentially execute arbitrary code if a user is tricked into installing a malicious Chrome Extension. While not actively exploited in the wild and lacking public exploit code, it has garnered some media attention, including a mention in Microsoft's March 2022 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 99.0.4844.51CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.