ZeroHour

CVE-2022-0609

KEVmass

Use-After-Free in Google Chromium Animation Component (Chrome, Edge, Opera)

CISA: Google Chromium Animation Use-After-Free Vulnerability

CVSS 3.1
8.8 high
EPSS
23%p98
Published
()
KEV added
AI analysis

CVE-2022-0609 is a use-after-free vulnerability (CWE-416) in the Animation component of Google's Chromium browser engine that can corrupt heap memory. A remote attacker triggers it by persuading a user to load a crafted HTML page (for example via a malicious or compromised website), with no authentication required beyond opening the page. Successful exploitation can lead to heap corruption and potentially arbitrary code execution in the context of the affected browser. Any browser or application built on Chromium is potentially affected, including Google Chrome, Microsoft Edge, and Opera. The flaw is actively exploited: CISA added it to the KEV catalog on 2022-02-15 with a required action to apply vendor updates, Google confirmed in-the-wild exploitation at disclosure, no public PoC is known, ransomware use is unknown, and EPSS assigns a 22.3% probability of exploitation within 30 days (98th percentile).

What to do: Apply the vendor updates immediately: Google fixed this in Chrome 98.0.4758.102 (February 2022), so update Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers or Chromium-embedded applications to releases containing that Chromium fix, and inventory browser versions across your fleet to catch machines lagging on the update. Until fully patched, treat unsolicited links to web pages as an exploitation vector given confirmed in-the-wild use, and comply with CISA's KEV required action to apply updates per vendor instructions.

Affected
Google Chromium (Animation component)Chromium prior to the 98.0.4758.102-era fix; exact version range not specified in the source data
Google ChromePrior to 98.0.4758.102 (per Google's February 2022 stable-channel advisory)
Microsoft Edge (Chromium-based)Builds incorporating pre-patch Chromium; fixed via the corresponding February 2022 Chromium update
Opera (Chromium-based)Builds incorporating pre-patch Chromium; fixed via the corresponding Chromium update
Estimated exposure
mass≈3 billion+ browser users (Chrome alone has an installed base exceeding 3 billion; Chromium also underlies Edge, Opera, and other Chromium-based browsers) — Chrome's global user base is publicly estimated at more than 3 billion, and Chromium's use as the engine for Microsoft Edge, Opera, and Chromium-embedded software extends exposure to nearly the entire desktop browsing population;…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium Animation
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news