ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Google Patches Chrome Zero Day Under Attack

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-2294
Heap Buffer Overflow in Google Chrome WebRTC Exploited in the Wild

CVE-2022-2294 is a heap buffer overflow (out-of-bounds write, CWE-787) in the WebRTC component used by Google Chrome. A remote attacker can trigger the flaw by luring a user to a crafted HTML page, and successful exploitation allows heap corruption with potential arbitrary code execution (CVSS 3.1: 8.8, high impact on confidentiality, integrity and availability). It affects Chrome prior to 103.0.5060.114 and, because the vulnerable code path resides in the shared WebRTC/WebKit component, it also affects Apple's iPhone OS, iPadOS, macOS/Mac OS X, tvOS and watchOS, WebKitGTK, WPE WebKit, Fedora and Extra Packages for Enterprise Linux (EPEL), and the WebRTC project library itself. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-08-25 with known ransomware use, and reporting indicates mercenary spyware operators used it as a Chrome zero-day; EPSS places its 30-day exploitation probability at 70.5%. Google fixed the flaw in Chrome 103.0.5060.114, and Apple and the WebKit/WPE maintainers issued their own security updates for affected products.

Do: Upgrade Google Chrome to 103.0.5060.114 or later on all managed and personal endpoints immediately. Apply Apple's released security updates for iPhone OS, iPadOS, macOS, tvOS and watchOS, and updated WebKitGTK, WPE WebKit and Fedora/EPEL packages for WebKit-based deployments. Given the CISA KEV listing, known ransomware use and 70.5% EPSS, prioritize patching and hunt for signs of exploitation (crafted-page lures and any linked spyware or ransomware activity) across browsers and WebKit applications.

8.870% KEV ransomware
  • google Chrome prior to 103.0.5060.114
  • webrtc project WebRTC affected component library per CISA; fixed in updated releases
  • apple iPhone OS affected releases; fixed via Apple security updates
  • +8 more
mass≈3+ billion Chrome users worldwide, plus additional users of Apple WebKit devices, WebKitGTK, WPE WebKit and Fedora/EPEL browser packages
CVE-2022-2295
+1 in the same advisory: …2296
Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

NVD description · AI analysis pending
8.81%
  • google chrome
  • google extra packages for enterprise linux
  • google fedora
Full article346 words · extracted from infosecurity-magazine.com · click to collapse

Google has released an update to its popular Chrome browser to fix four vulnerabilities, including one zero-day current being exploited by attackers.

The new Chrome version 103.0.5060.114 will be rolled out to Windows users over the coming days and weeks, according to a Google advisory.

It includes the high severity CVE-2022-2294, a heap buffer overflow bug in WebRTC. It was reported by Avast researcher Jan Vojtesek on July 1.

“We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel,” Google said. “Google is aware that an exploit for CVE-2022-2294 exists in the wild.”

There was no additional information at the time of writing on how the zero-day is being exploited, by whom and for what purpose.

However, Google released details of two other high-severity vulnerabilities found by external researchers, which it fixed in the update.

CVE-2022-2295 is a type confusion bug in the V8 JavaScript engine, and CVE-2022-2296 is a use-after-free (UAF) flaw in the Chrome OS Shell.

Patrick Tiquet, VP of security & architecture at Keeper Security, explained that CVE-2022-2294 could lead to arbitrary remote code execution simply by visiting a malicious website.

“This could enable an attacker to perform a variety of actions on a target system, such as install malware or steal information. Web browsers are essential applications that nearly all cloud-based services have in common and are therefore high-priority targets – compromise of a web browser could be leveraged to compromise any cloud-based service accessed by that browser,” he added.

“Ensuring that web browsers are patched is a user or customer organization responsibility. Web browsers, if not maintained and patched, can be a weak link in the security of any cloud-based service. Client web browsers should be particularly concerning to cloud services in this case because they are largely outside of the security controls of the cloud service provider.”

This is the fourth Chrome zero-day bug that Google has been forced to fix so far this year after updates in February, March and April.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/google-patches-chrome-zero-day/