CVE-2022-1640 is a use-after-free vulnerability in the Sharing component of Google Chrome versions prior to 101.0.4951.64. A remote attacker could exploit this by convincing a user to engage in specific UI interactions, leading to heap corruption via a crafted HTML page. This vulnerability is rated 8.8 HIGH on the CVSS scale, indicating a severe risk. It has a low attack complexity and requires user interaction, but successful exploitation could result in high impact to confidentiality, integrity, and availability. There is no evidence of active exploitation (KEV: No), nor are there public exploit modules available (Metasploit, Nuclei, ExploitDB: None). Despite this, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 101.0.4951.64CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.