Junglewise Threat Intelligence

CVE-2022-0609: Use after free in Animation

CVE-2022-0609 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2022-02-22

Technologies: CefSharp.Wpf.HwndHost (NuGet), CefSharp.Common (NuGet), Microsoft Edge, Opera Software Opera, CefSharp.Common.NETCore (NuGet), Google Chrome, CefSharp.Wpf (NuGet), CefSharp.WinForms (NuGet). Vendors: NuGet, Google, Microsoft, Opera Software.

Executive brief

A use-after-free vulnerability exists in the Animation component of Google Chromium. A remote attacker can exploit this via a specially crafted HTML page to cause heap corruption, potentially leading to arbitrary code execution.

Affected products

  • Google Chrome prior to 98.0.4758.102
  • Microsoft Edge
  • Opera Software Opera

Timeline

  • 2022-02-14: patched: Stable channel update for desktop released (98.0.4758.102)
  • 2022-02-15: disclosed: Vulnerability published and added to CISA KEV catalog
  • 2022-02-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-02-15: exploited: Reported as exploited in the wild at time of publication

Related threats