CVE-2022-1096
KEVmass1Actively Exploited Type Confusion in Chromium V8 Engine (Chrome, Edge, Opera)
CISA: Google Chromium V8 Type Confusion Vulnerability
Google Chromium's V8 JavaScript engine contains a type confusion flaw (CWE-843) that a remote attacker can trigger by getting a user to open a crafted HTML page, causing heap corruption and potentially enabling code execution in the browser renderer. Because V8 underpins all Chromium-based browsers, Google Chrome, Microsoft Edge, Opera, and any other Chromium-derived browser built before the late-March 2022 fixes are affected. A successful exploit yields heap corruption in the renderer, which attackers typically use to run code in the browser process and often chain with sandbox escapes for broader system compromise. The vulnerability is confirmed exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-28 with a required action of applying vendor updates — and EPSS assigns a 24.4% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known. CVSS scoring was not yet available at the time of this data.
What to do: Update Chromium-based browsers immediately — Google Chrome to 99.0.4844.84 or later, Microsoft Edge to 99.0.1150.55 or later, and Opera to its equivalent Chromium 99 build — and verify versions via chrome://version or edge://version. There is no server-side mitigation because exploitation occurs when a user loads attacker-crafted HTML, so prioritize endpoint browser patching and rebuild any applications that embed Chromium (e.g., Electron apps) on patched V8.
| Google Chromium V8 JavaScript engine | — |
| Google Chrome (Chromium-based) | desktop stable prior to 99.0.4844.84 |
| Microsoft Edge (Chromium-based) | Chromium 99-based builds prior to the late-March 2022 update (Edge 99.0.1150.55 equivalent) |
| Opera browser (Chromium-based) | Chromium 99-based builds prior to the late-March 2022 update (99.0.4844.84 equivalent) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- Affected
- Google Chromium V8
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Products
- chrome
- Weakness
- CWE-843
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H