ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Google Chrome zero-day exploited in the wild (CVE-2022-4262)

criticalExploit / PoC exploited in the wildimportance 60CVE-2022-4262

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-4262
Type Confusion in Google Chrome V8 JavaScript Engine Exploited in the Wild (CVE-2022-4262)

CVE-2022-4262 is a type confusion vulnerability in the V8 JavaScript engine used by Google Chrome, in which incorrect handling of object types can lead to heap corruption. An attacker can trigger the flaw by convincing a user to visit a specially crafted HTML page, with no privileges or special network access required. Successful exploitation could allow remote code execution or information disclosure within the browser process, and the High severity rating and web-reachable attack vector reflect significant potential impact. All Google Chrome users running versions prior to 108.0.5359.94 are affected, as are users of Chromium-based browsers incorporating the vulnerable V8 code. The vulnerability was a zero-day exploited in the wild prior to the patch — attributed by media reports to commercial spyware vendors targeting Android and iOS devices — and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-12-05.

Do: Update Google Chrome to 108.0.5359.94 or later on all endpoints, and apply equivalent updates from vendors of Chromium-based browsers (e.g., Microsoft Edge, Brave, Opera) as they ship patched V8 builds. Verify the fixed version is running via chrome://settings/help or your patch-management inventory, and treat browser exploit chains as a spyware risk: review endpoint telemetry for signs of compromise, especially on mobile or high-target devices. CISA's required action is to apply updates per vendor instructions.

8.816% KEV
  • Google Chrome All versions prior to 108.0.5359.94
  • Google Chromium V8 V8 as shipped in Google Chrome prior to 108.0.5359.94
massWell over 1 billion users (Chrome has roughly 60%+ desktop browser market share and billions of active installs; unknown how many remain on pre-108.0.5359.94…
Full article255 words · extracted from helpnetsecurity.com · click to collapse

Google has patched CVE-2022-4262, a type confusion vulnerability in the V8 JavaScript engine used by Google Chrome (and Chromium), which is being exploited by attackers in the wild.

CVE-2022-4262

No other technical details have been shared about this zero-day flaw, only that it was reported by security engineer Clement Lecigne of Google’s Threat Analysis Group (TAG), whose goal is to protect users from state-sponsored attacks and other advanced persistent threats.

About CVE-2022-4262

With a “High” security rating, CVE-2022-4262 ostensibly allows remote attackers to exploit heap (memory) corruption via a crafted HTML page.

“Access to bug details and links may be kept restricted until a majority of users are updated with a fix,” Srinivas Sista, Technical program manager for Google Chrome, explained.

The fix – in the form of a browser update – is being rolled out right now. Users will get updated to v108.0.5359.94 (for Mac and Linux) and v108.0.5359.94/.95 (for Windows) if the update is available and they reboot their browser. Users can also trigger the update manually and should consider doing it.

The fix for this bug can also be found in the latest update for the Microsoft’s Edge browser (v108.0.1462.41), as it’s based on the open-source Chromium project. Users should update this browser as well.

Finally, CVE-2022-4262 has been added to CISA’s Known Exploited Vulnerabilities catalog, “a living list of known CVEs that carry significant risk to the federal enterprise.” This means that agencies of the US federal civilian executive branch are required to apply the patches by December 26, 2022.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/12/06/cve-2022-4262/