Google fixed third zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-0609 | Use-After-Free in Google Chromium Animation Component (Chrome, Edge, Opera) CVE-2022-0609 is a use-after-free vulnerability (CWE-416) in the Animation component of Google's Chromium browser engine that can corrupt heap memory. A remote attacker triggers it by persuading a user to load a crafted HTML page (for example via a malicious or compromised website), with no authentication required beyond opening the page. Successful exploitation can lead to heap corruption and potentially arbitrary code execution in the context of the affected browser. Any browser or application built on Chromium is potentially affected, including Google Chrome, Microsoft Edge, and Opera. The flaw is actively exploited: CISA added it to the KEV catalog on 2022-02-15 with a required action to apply vendor updates, Google confirmed in-the-wild exploitation at disclosure, no public PoC is known, ransomware use is unknown, and EPSS assigns a 22.3% probability of exploitation within 30 days (98th percentile). Do: Apply the vendor updates immediately: Google fixed this in Chrome 98.0.4758.102 (February 2022), so update Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers or Chromium-embedded applications to releases containing that Chromium fix, and inventory browser versions across your fleet to catch machines lagging on the update. Until fully patched, treat unsolicited links to web pages as an exploitation vector given confirmed in-the-wild use, and comply with CISA's KEV required action to apply updates per vendor instructions. | 8.8 | 23% | KEV |
| mass≈3 billion+ browser users (Chrome alone has an installed base exceeding 3 billion; Chromium also underlies Edge, Opera, and other Chromium-based browsers) | |
| CVE-2022-1096 | Actively Exploited Type Confusion in Chromium V8 Engine (Chrome, Edge, Opera) Google Chromium's V8 JavaScript engine contains a type confusion flaw (CWE-843) that a remote attacker can trigger by getting a user to open a crafted HTML page, causing heap corruption and potentially enabling code execution in the browser renderer. Because V8 underpins all Chromium-based browsers, Google Chrome, Microsoft Edge, Opera, and any other Chromium-derived browser built before the late-March 2022 fixes are affected. A successful exploit yields heap corruption in the renderer, which attackers typically use to run code in the browser process and often chain with sandbox escapes for broader system compromise. The vulnerability is confirmed exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-28 with a required action of applying vendor updates — and EPSS assigns a 24.4% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known. CVSS scoring was not yet available at the time of this data. Do: Update Chromium-based browsers immediately — Google Chrome to 99.0.4844.84 or later, Microsoft Edge to 99.0.1150.55 or later, and Opera to its equivalent Chromium 99 build — and verify versions via chrome://version or edge://version. There is no server-side mitigation because exploitation occurs when a user loads attacker-crafted HTML, so prioritize endpoint browser patching and rebuild any applications that embed Chromium (e.g., Electron apps) on patched V8. | 8.8 | 24% | KEV |
| mass≈3+ billion users (effectively all Chromium-based browser installs worldwide) | |
| CVE-2022-1364 | Actively Exploited V8 Turbofan Type Confusion in Google Chrome (CVE-2022-1364) CVE-2022-1364 is a type confusion flaw (CWE-843) in the Turbofan JIT compiler of the V8 JavaScript engine, as shipped in Google Chrome. A remote attacker can trigger it by persuading a user to open a crafted HTML page, and successful exploitation can lead to heap corruption in the browser renderer. Per the CVSS vector, no privileges are required but user interaction is needed, with high potential impact on confidentiality, integrity, and availability. Anyone running Google Chrome prior to 100.0.4896.127 — and, per CISA's designation, the affected Google Chromium V8 component — is exposed until patched. The bug was exploited as a zero-day in the wild (reported as the ninth actively exploited Chrome zero-day of 2022), was added to CISA's KEV catalog on 2022-04-15, and carries a 13.7% probability of exploitation in the next 30 days (96th EPSS percentile). Do: Update Google Chrome immediately to 100.0.4896.127 or later on all platforms, as required by the vendor and by CISA's KEV required action. Organizations using Chromium-based browsers (Edge, Brave, Opera, Vivaldi, etc.) should verify their vendors have shipped the corresponding V8 fix rather than waiting on version numbers. Given exploitation via crafted web pages, scan endpoint inventories for Chrome versions below 100.0.4896.127 and prioritize user-facing fleets. | 8.8 | 14% | KEV PoC |
| massbillions of user installations (Chrome held roughly 65% of desktop browser share in 2022) |
Full article262 words · extracted from securityaffairs.com · click to collapse

Google Chrome 100.0.4896.127 addresses a new high-severity zero-day vulnerability tracked as CVE-2022-1364, actively exploited by threat actors in the wild.
Google has released Chrome 100.0.4896.127 for Windows, Mac, and Linux to address a high-severity zero-day, tracked as CVE-2022-1364, that is actively exploited by threat actors in attacks.
The CVE-2022-1364 zero-day is a type confusion issue that resides in the V8 JavaScript engine that was reported by Clément Lecigne of Google’s Threat Analysis Group on April 13, 2022.
Shane Huntley, Google’s Threat Analysis Group chief, highlighted that the flaw was quicky addressed by the company.
“Google is aware that an exploit for CVE-2022-1364 exists in the wild,” reads the security advisory.
The IT giant did not provide technical details about the attacks, as usual, it plans to keep them restricted to give the time to the users to install the security fix.
This is the third Chome zero-day vulnerability addressed by the company this year, previous bugs fixed by the company are CVE-2022-1096 (Type Confusion in V8 JavaScript engine fixed on March 25) and CVE-2022-0609 (a use after free issue that resides in Animation February fixed on February 14).
Please vote for Security Affairs as the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS
Vote for me in the sections “The Underdogs – Best Personal (non-commercial) Security Blog” and “The Tech Whizz – Best Technical Blog” and others of your choice.
To nominate, please visit: https://docs.google.com/forms/d/e/1FAIpQLSfxxrxICiMZ9QM9iiPuMQIC-IoM-NpQMOsFZnJXrBQRYJGCOw/viewform
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Google Chrome)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/130213/security/google-chrome-zeroday-cve-2022-1364.html