CVE-2022-1633 is a use-after-free vulnerability in the Sharesheet component of Google Chrome on Chrome OS, affecting versions prior to 101.0.4951.64. This high-severity vulnerability (CVSS 8.8) allows a remote attacker to potentially exploit heap corruption, leading to high impacts on confidentiality, integrity, and availability, by tricking a user into specific UI interactions. While the vulnerability requires user interaction, there is currently no evidence of active exploitation, nor are there public exploit modules available in common frameworks. Despite this, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 101.0.4951.64CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.