VDB
CVE-2022-0609
CVE-2022-0609
PUBLISHED
CVSS 8.8 HIGH
Reported by Chrome · Published April 4, 2022
Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Risk Scores
CVSS 3.1
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chrome | unspecified | |
| alpine | qt5-qtwebengine | 0, 0, 0 |
| Chrome | unspecified | |
| alpine | chromium | 0, 0, 0 |
Exploit Intelligence
- Use-after-free in Animation (Google Chrome) (gpz)
- Use-after-free in Animation (Google Chrome) (gpz)
- Use-after-free in Animation (Google Chrome) (gpz)
- Use-after-free in Animation (Google Chrome) (gpz)
- Use-after-free in Animation (Google Chrome) (gpz)
- ba_variablemanager.java (github-poc)
- ba_variablemanager.java (github-poc)
- ba_variablemanager.java (github-poc)
- ba_variablemanager.java (github-poc)
- ba_variablemanager.java (github-poc)
…and 16 more exploits
Timeline
- Feb 15, 2022 CISA KEV Added
- Feb 15, 2022 PoC Published
- Feb 17, 2022 CVE Published
- Feb 26, 2022 CVE Updated
- Apr 5, 2022 EPSS Score
- Jul 23, 2023 EPSS Score
- Sep 28, 2023 EPSS Score
- Oct 26, 2023 EPSS Score
- May 28, 2024 EPSS Score
- Jul 8, 2024 EPSS Score
- Mar 17, 2025 EPSS Score
- Mar 20, 2025 EPSS Score
References
- x_refsource_MISC
- x_refsource_MISC
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-0609 url