ZeroHour

CVE-2022-3723

KEVmass1

Actively Exploited V8 Type Confusion in Google Chrome (CVE-2022-3723)

CISA: Google Chromium V8 Type Confusion Vulnerability

CVSS 3.1
8.8 high
EPSS
8%p94
Published
()
KEV added
AI analysis

CVE-2022-3723 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine used by Google Chrome, rated High severity with a CVSS 3.1 score of 8.8. It is triggered remotely when a user renders a crafted HTML page, allowing a remote attacker to potentially exploit heap corruption in the browser; the high confidentiality, integrity, and availability impact reflects likely code execution. All Google Chrome releases prior to 107.0.5304.87 are affected, and per CISA the underlying flaw resides in Google Chromium V8, so Chromium-based browsers embedding the same engine are similarly exposed pending their own updates. The flaw was exploited as a zero-day: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-10-28, and news coverage describes it as Google's ninth actively exploited Chrome zero-day of 2022, amid reports of spyware vendors exploiting zero-days in the wild. EPSS assigns a 7.9% probability (94th percentile) of exploitation activity in the next 30 days.

What to do: Update Google Chrome to 107.0.5304.87 or later on all endpoints and restart the browser to complete the patch, verifying the installed version via chrome://version; apply the corresponding V8/Chromium update in any Chromium-based browsers your organization ships. CISA's KEV required action is to apply updates per vendor instructions, so prioritize managed fleets, user workstations, and any browsers exposed to untrusted web content. No public PoC or workaround is known, so patching is the sole effective mitigation.

Affected
Google Chromeall versions prior to 107.0.5304.87 (flaw is in the V8 engine, identified by CISA as Google Chromium V8)
Estimated exposure
mass≈3 billion users (Chrome's global install base across desktop and mobile) — Chrome holds roughly two-thirds of global browser usage share, so an unpatched V8 flaw plausibly affects the entire multi-billion-user Chrome population until version 107.0.5304.87 is auto-deployed, with additional exposure from…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
google
Products
chrome
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news