CVE-2022-0097: Inappropriate implementation in DevTools
Inappropriate implementation in DevTools in Google Chrome prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to to potentially allow extension to escape the sandbox via a crafted HTML page.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-0096
- CVE-2022-0098
- CVE-2022-0099
- CVE-2022-0100
- CVE-2022-0101
- CVE-2022-0337
- CVE-2022-0102
- CVE-2022-0103
- CVE-2022-4924
- CVE-2022-0104
- CVE-2022-0105
- CVE-2022-0106
- CVE-2022-0107
- CVE-2022-0108
- CVE-2022-0109
- CVE-2022-0110
- CVE-2022-0111
- CVE-2022-0112
- CVE-2022-0113
- CVE-2022-0114
- CVE-2022-0115
- CVE-2022-0116
- CVE-2022-0117
- CVE-2022-0118
- CVE-2022-0120
- CVE-2022-4925
Frequently Asked Questions
What is the severity of CVE-2022-0097?
CVE-2022-0097 is classified as a high severity vulnerability due to its potential to allow malicious extensions to escape the sandbox in Google Chrome.
How do I fix CVE-2022-0097?
To fix CVE-2022-0097, update Google Chrome to version 97.0.4692.71 or later.
Which versions of Google Chrome are affected by CVE-2022-0097?
Google Chrome versions prior to 97.0.4692.71 are affected by CVE-2022-0097.
What platforms are impacted by CVE-2022-0097?
CVE-2022-0097 affects Google Chrome on all supported operating systems including Windows, macOS, and Linux.
Can CVE-2022-0097 affect Chromium projects?
Yes, CVE-2022-0097 can also affect Chromium versions up to 90.0.4430.212 and earlier.