Skip to content
COOEY

EXPOSURES › CVE-2022-0609

CVE-2022-0609

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-02-15 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-0609 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

A use-after-free vulnerability in Google Chromium's animation code allowed remote attackers to exploit heap corruption via crafted HTML pages.

This use-after-free flaw in Chromium's animation subsystem enabled remote code execution via heap corruption, affecting major browsers like Chrome and Edge. DIB organizations must ensure their browsers are patched against this actively exploited vulnerability to prevent ransomware or data breaches. The failure stems from unpatched, exploitable code in a widely deployed software supply chain.

Shame score — A known, actively exploited vulnerability in a foundational browser engine that could be weaponized for ransomware or data exfiltration, representing a severe supply-chain risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized