Google releases emergency security update for Chrome users after second 0
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-0609 | Use-After-Free in Google Chromium Animation Component (Chrome, Edge, Opera) CVE-2022-0609 is a use-after-free vulnerability (CWE-416) in the Animation component of Google's Chromium browser engine that can corrupt heap memory. A remote attacker triggers it by persuading a user to load a crafted HTML page (for example via a malicious or compromised website), with no authentication required beyond opening the page. Successful exploitation can lead to heap corruption and potentially arbitrary code execution in the context of the affected browser. Any browser or application built on Chromium is potentially affected, including Google Chrome, Microsoft Edge, and Opera. The flaw is actively exploited: CISA added it to the KEV catalog on 2022-02-15 with a required action to apply vendor updates, Google confirmed in-the-wild exploitation at disclosure, no public PoC is known, ransomware use is unknown, and EPSS assigns a 22.3% probability of exploitation within 30 days (98th percentile). Do: Apply the vendor updates immediately: Google fixed this in Chrome 98.0.4758.102 (February 2022), so update Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers or Chromium-embedded applications to releases containing that Chromium fix, and inventory browser versions across your fleet to catch machines lagging on the update. Until fully patched, treat unsolicited links to web pages as an exploitation vector given confirmed in-the-wild use, and comply with CISA's KEV required action to apply updates per vendor instructions. | 8.8 | 23% | KEV |
| mass≈3 billion+ browser users (Chrome alone has an installed base exceeding 3 billion; Chromium also underlies Edge, Opera, and other Chromium-based browsers) | |
| CVE-2022-1096 | Actively Exploited Type Confusion in Chromium V8 Engine (Chrome, Edge, Opera) Google Chromium's V8 JavaScript engine contains a type confusion flaw (CWE-843) that a remote attacker can trigger by getting a user to open a crafted HTML page, causing heap corruption and potentially enabling code execution in the browser renderer. Because V8 underpins all Chromium-based browsers, Google Chrome, Microsoft Edge, Opera, and any other Chromium-derived browser built before the late-March 2022 fixes are affected. A successful exploit yields heap corruption in the renderer, which attackers typically use to run code in the browser process and often chain with sandbox escapes for broader system compromise. The vulnerability is confirmed exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-28 with a required action of applying vendor updates — and EPSS assigns a 24.4% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known. CVSS scoring was not yet available at the time of this data. Do: Update Chromium-based browsers immediately — Google Chrome to 99.0.4844.84 or later, Microsoft Edge to 99.0.1150.55 or later, and Opera to its equivalent Chromium 99 build — and verify versions via chrome://version or edge://version. There is no server-side mitigation because exploitation occurs when a user loads attacker-crafted HTML, so prioritize endpoint browser patching and rebuild any applications that embed Chromium (e.g., Electron apps) on patched V8. | 8.8 | 24% | KEV |
| mass≈3+ billion users (effectively all Chromium-based browser installs worldwide) |
Full article477 words · extracted from therecord.media · click to collapse
Google has released an urgent update for a 0-day vulnerability found on March 23 affecting Chrome. Google gave CVE-2022-1096 a high severity rating and said an exploit for the vulnerability exists in the wild. Google patched the bug for Windows, Mac, and Linux operating systems users in Chrome 99.0.4844.84. Microsoft also released a warning about the issue and patched it for Edge users. Little information is available about the issue but experts said it is tied to V8, Google’s open source JavaScript engine. The vulnerability was submitted anonymously, according to Google. Bugcrowd CTO Casey Ellis said the first thing that stood out about the update is that it only fixes a single issue. “This is pretty unusual for Google – they usually fix multiple issues in these types of releases – which suggests that they are quite concerned and very motivated to see fixes against CVE-2022-1096 applied across their user-base ASAP,” Ellis said. “The second thing is the speed of the patch being rolled out. The vulnerability was only reported on the 23rd of March, and while Google’s Chrome team tends to be fairly prompt in developing, testing, and rolling patches, the idea of a patch for software deployed as widely as Chrome in 48 hours is something I continue to be impressed by.” Michael Freeman, CTO of Cyber Threat Cognitive Intel (CTCI), said the vulnerability is a “type confusion” in the V8 JavaScript engine exploit, explaining that V8 is Chrome’s component that handles processing JavaScript code. A type confusion refers to coding bugs during which an app initializes data execution operations using the input of a specific “type” but is tricked into processing the incorrect input as a different “type,” he said. “This leads to logical errors in the application’s memory, allowing an attacker to run unrestricted malicious codes inside an application. “CTCI identified exploitation of this vulnerability on 03/20/2022 but could not match it to any known CVEs. Additional intelligence was found during the attack analysis on 3/25/2022, where we identified a phishing scam against a honey client that is used to identify client-side attacks on users within the crypto space. The initial vector was a Discord channel.” This is the second 0-day in Chrome that Google has announced this year. Just last week the tech giant said North Korean hackers had exploited CVE-2022-0609 – which was patched in a February release – during two separate hacking campaigns. Google Threat Analysis Group’s Adam Weidemann explained that on February 10, the company discovered two different North Korean campaigns – which they attributed to Operation Dream Job and Operation AppleJeus – exploiting the vulnerability.
No previous article
No new articles
Andrea Peterson
(they/them) is a longtime cybersecurity journalist who cut their teeth covering technology policy at ThinkProgress (RIP) and The Washington Post before doing deep-dive public records investigations at the Project on Government Oversight and American Oversight.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/google-releases-emergency-security-update-for-chrome-users-after-second-0-day-of-2022-discovered