FlawAtlas
Search the atlas
CVE-2022-0609 High

Confirmed as exploited

CVE-2022-0609

Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Exploit probability 20.8%
Published April 5, 2022
Required by March 1, 2022
Last source change March 14, 2026

01 / ACTION

Required action

Apply updates per vendor instructions.

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown
NuGet CefSharp.Wpf.HwndHost

22 explicit affected versions

NuGet CefSharp.Common

126 explicit affected versions

NuGet CefSharp.Common.NETCore

38 explicit affected versions

NuGet CefSharp.OffScreen

120 explicit affected versions

NuGet CefSharp.OffScreen.NETCore

38 explicit affected versions

NuGet CefSharp.WinForms

125 explicit affected versions

NuGet CefSharp.WinForms.NETCore

38 explicit affected versions

NuGet CefSharp.Wpf

133 explicit affected versions

NuGet CefSharp.Wpf.NETCore

38 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities CVE-2022-0609

Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

View original source
Open Source Vulnerabilities CVE-2022-0609

Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

View original source
Open Source Vulnerabilities GHSA-vv6j-ww6x-54gx

CVE-2022-0609: Use after free in Animation - https://chromereleases.googleblog.com/2022/02/stable-channel-update-for-desktop_14.html - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0609 Google is aware of reports that exploits for CVE-2022-0609 exist in the wild. The exploitation is known to be easy. The attack may be initiated remotely. No form of authentication is needed for a successful exploitation. It demands that the victim is doing some kind of user interaction. Technical details are unknown but an exploit is available. There is currently little other public information on the issue other than it has been flagged as `High` severity.

View original source

05 / REFERENCES

Further evidence