CISA adds Google zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-4262 | Type Confusion in Google Chrome V8 JavaScript Engine Exploited in the Wild (CVE-2022-4262) CVE-2022-4262 is a type confusion vulnerability in the V8 JavaScript engine used by Google Chrome, in which incorrect handling of object types can lead to heap corruption. An attacker can trigger the flaw by convincing a user to visit a specially crafted HTML page, with no privileges or special network access required. Successful exploitation could allow remote code execution or information disclosure within the browser process, and the High severity rating and web-reachable attack vector reflect significant potential impact. All Google Chrome users running versions prior to 108.0.5359.94 are affected, as are users of Chromium-based browsers incorporating the vulnerable V8 code. The vulnerability was a zero-day exploited in the wild prior to the patch — attributed by media reports to commercial spyware vendors targeting Android and iOS devices — and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-12-05. Do: Update Google Chrome to 108.0.5359.94 or later on all endpoints, and apply equivalent updates from vendors of Chromium-based browsers (e.g., Microsoft Edge, Brave, Opera) as they ship patched V8 builds. Verify the fixed version is running via chrome://settings/help or your patch-management inventory, and treat browser exploit chains as a spyware risk: review endpoint telemetry for signs of compromise, especially on mobile or high-target devices. CISA's required action is to apply updates per vendor instructions. | 8.8 | 16% | KEV |
| massWell over 1 billion users (Chrome has roughly 60%+ desktop browser market share and billions of active installs; unknown how many remain on pre-108.0.5359.94… |
Full article485 words · extracted from therecord.media · click to collapse
The Cybersecurity and Infrastructure Security Agency (CISA) added the latest Google Chrome zero-day to its catalog of exploited vulnerabilities on Monday evening, ordering federal civilian agencies to patch the bug by December 26. Google’s Srinivas Sista announced the vulnerability – CVE-2022-4262 – on Friday, giving it a high severity rating. Google noted that it was reported by Clement Lecigne of Google's Threat Analysis Group on November 29 and that an exploit for the bug existed in the wild. The tech giant offered few details about the issue, only writing that it was a type confusion in V8 – meaning Google V8's javascript engine. “Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed,” Sista wrote. CISA added that specific impacts from exploitation “are not available at this time.” Experts said the lack of information made it difficult to discern how serious the issue is and added that Chrome typically makes it easy for users to update their browsers thanks to a yellow or red “Update” tag next to the search bar. Vulcan Cyber’s Mike Parkin said it appears that an attacker could compromise a victim when they simply visit a website that hosts malicious HTML code but said the update process “is straightforward.” Mike Walters, vice president of vulnerability and threat research at Action1, added that the vulnerability affects all versions of the browser on all platforms. “This fix addresses the ninth zero-day vulnerability in the browser this year. Moreover, it continues an odd pattern of Google fixing a zero-day vulnerability soon after a regular release,” Walters explained. “‘Type Confusion in V8’ vulnerabilities are related to the browser’s JavaScript engine. Accordingly, it is very likely that this vulnerability allows remote code execution, which means that a threat actor could cause any script or malware payload to be executed on the victims’ device.” While Google makes it simple to update browsers, patching can be problematic at times because many people do not like rebooting their browsers – something that is typically required as part of an update, Walters said. He suggested organizations automate patching for third-party apps, including browsers, and ensure their IT teams can force reboots remotely in a way that is comfortable to end users. Google announced the eighth exploited zero-day just two weeks ago on November 25, with the others coming in February, March, April, July, August and October.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-adds-google-zero-day-to-exploited-vulnerabilities-list