Skip to content

Use after free in Animation

High
amaitland published GHSA-vv6j-ww6x-54gx Feb 18, 2022

Package

nuget CefSharp.Common (NuGet)

Affected versions

<= 98.1.190

Patched versions

98.1.210
nuget CefSharp.Common.NETCore (NuGet)
<= 98.1.190
98.1.210
nuget CefSharp.OffScreen (NuGet)
<= 98.1.190
98.1.210
nuget CefSharp.OffScreen.NETCore (NuGet)
<= 98.1.190
98.1.210
nuget CefSharp.WinForms (NuGet)
<= 98.1.190
98.1.210
nuget CefSharp.WinForms.NETCore (NuGet)
<= 98.1.190
98.1.210
nuget CefSharp.Wpf (NuGet)
<= 98.1.190
98.1.210
nuget CefSharp.Wpf.HwndHost (NuGet)
<= 98.1.190
98.1.210
nuget CefSharp.Wpf.NETCore (NuGet)
<= 98.1.190
98.1.210

Description

CVE-2022-0609: Use after free in Animation

Google is aware of reports that exploits for CVE-2022-0609 exist in the wild.

The exploitation is known to be easy. The attack may be initiated remotely. No form of authentication is needed for a successful exploitation. It demands that the victim is doing some kind of user interaction. Technical details are unknown but an exploit is available.

There is currently little other public information on the issue other than it has been flagged as High severity.

Severity

High

CVE ID

CVE-2022-0609

Weaknesses

No CWEs