Google Releases Chrome Patch to Fix New Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-2294 | Heap Buffer Overflow in Google Chrome WebRTC Exploited in the Wild CVE-2022-2294 is a heap buffer overflow (out-of-bounds write, CWE-787) in the WebRTC component used by Google Chrome. A remote attacker can trigger the flaw by luring a user to a crafted HTML page, and successful exploitation allows heap corruption with potential arbitrary code execution (CVSS 3.1: 8.8, high impact on confidentiality, integrity and availability). It affects Chrome prior to 103.0.5060.114 and, because the vulnerable code path resides in the shared WebRTC/WebKit component, it also affects Apple's iPhone OS, iPadOS, macOS/Mac OS X, tvOS and watchOS, WebKitGTK, WPE WebKit, Fedora and Extra Packages for Enterprise Linux (EPEL), and the WebRTC project library itself. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-08-25 with known ransomware use, and reporting indicates mercenary spyware operators used it as a Chrome zero-day; EPSS places its 30-day exploitation probability at 70.5%. Google fixed the flaw in Chrome 103.0.5060.114, and Apple and the WebKit/WPE maintainers issued their own security updates for affected products. Do: Upgrade Google Chrome to 103.0.5060.114 or later on all managed and personal endpoints immediately. Apply Apple's released security updates for iPhone OS, iPadOS, macOS, tvOS and watchOS, and updated WebKitGTK, WPE WebKit and Fedora/EPEL packages for WebKit-based deployments. Given the CISA KEV listing, known ransomware use and 70.5% EPSS, prioritize patching and hunt for signs of exploitation (crafted-page lures and any linked spyware or ransomware activity) across browsers and WebKit applications. | 8.8 | 70% | KEV ransomware |
| mass≈3+ billion Chrome users worldwide, plus additional users of Apple WebKit devices, WebKitGTK, WPE WebKit and Fedora/EPEL browser packages | |
| CVE-2022-4135 | Chromium GPU heap buffer overflow enables sandbox escape (affects Chrome, Edge, Opera) CVE-2022-4135 is a heap buffer overflow (CWE-787, out-of-bounds write) in the GPU process of Google Chromium, the browser engine behind Chrome and most other major browsers. It is triggered via a crafted HTML page and, per CISA, requires the attacker to have already compromised the browser's renderer process; the memory corruption in the GPU process can then be leveraged to escape the renderer sandbox. A successful attack moves the attacker out of the tightly restricted renderer sandbox toward the higher-privilege GPU process on the host, a step that can enable further code execution. All users of Chromium-based browsers are affected — CISA explicitly lists Google Chrome, Microsoft Edge, and Opera, among others — though no specific vulnerable version ranges are published in the source data. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-11-28, EPSS assigns a 31.9% probability of exploitation within 30 days (98th percentile), and no public proof-of-concept is known. Do: Treat unpatched Chromium-based browsers as exposed and apply vendor updates immediately, per CISA's required action: update Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers to the latest patched releases available as of the late-November 2022 KEV listing. Inventory managed endpoints for browser versions and verify auto-update is enabled, since the flaw is confirmed exploited in the wild even though no public PoC exists. | 9.6 | 32% | KEV PoC |
| mass≈billions of users across Google Chrome, Microsoft Edge, Opera and other Chromium-based browsers (exact count unknown) |
Full article296 words · extracted from infosecurity-magazine.com · click to collapse
Google released new software patches on Thursday to address a new zero-day vulnerability in its Chrome web browser.
Writing in a security bulletin, the tech giant described the high-severity vulnerability (tracked CVE-2022-4135) as a heap buffer overflow in the graphics processing unit (GPU) component.
Google attributed the discovery of the vulnerability to Clement Lecigne from its Threat Analysis Group (TAG), saying the researcher made the discovery on November 24.
The new vulnerability marks the eighth zero-day fixed by Google for the desktop version of the Chrome web browser.
The company is recommending users upgrade to version 107.0.5304.121/.122 for Windows and 107.0.5304.121 for Mac and Linux. Chromium-based browsers like Microsoft Edge, Brave, Opera and Vivaldi should also be updated to apply the fixes as and when they become available.
Google is also currently withholding details about the vulnerability to prevent expanding its malicious exploitation.
While the full scope of the exploit is currently unknown, this type of vulnerability can typically enable threat actors to corrupt data and remotely execute code on a victim's machine.
In fact, according to the US government's National Institute of Standards and Technology (NIST) agency, CVE-2022-4135 allows a "remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page."
Patches for the vulnerability should be applied automatically. If that's not the case because of system settings, users can upgrade their Chrome browser by clicking on the three vertical dots in the upper-right corner and navigating to 'Help' and then 'About Google Chrome.'
The browser will then automatically check for and download the latest build (107.0.5304.121) and prompt users to restart their browser.
Some of the other zero-day Chrome vulnerabilities discovered by Google this year include the CVE-2022-2294, which the company patched in July.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/chrome-patch-fix-zero-day/