Thursday, December 5, 2024
HomeChromeGoogle Chrome High-Severity Zero-Day Flaw Exploited in The Wild - Emergency Patch!!

Google Chrome High-Severity Zero-Day Flaw Exploited in The Wild – Emergency Patch!!

Published on

SIEM as a Service

In response to the active exploit of an open high-severity zero-day vulnerability (CVE-2022-4262) in the Chrome web browser, Google has released an emergency security patch to address the issue.

Actively exploited Chrome zero-day vulnerability that allows attackers to execute an arbitrary code to take full control of the system remotely using the exploit that exists in the Wild.

Since the beginning of the year, Chrome has patched a total of nine zero-day vulnerabilities, including this one that was exploited in the wild. As a security patch, Google released Chrome 108.0.5359.94/.95 for the following major platforms:-

- Advertisement - SIEM as a Service
  • Windows
  • Mac
  • Linux

In the wild, an exploit for CVE-2022-4262 has been reported, and Google is aware of all these reports. As of now, Stable Desktop channel users have started to receive the new version as part of the rolling-out process. Within a few days or a few weeks, it will be reached by the entire user base.

Zero-Day Flaw Profile

  • CVE ID: CVE-2022-4262
  • Severity: High
  • Description: Type Confusion in V8
  • Reporting: It was reported on 2022-11-29

Successful exploitation of this zero-day bug leads to crashes of the browser by reading or writing memory out of buffer bounds.

V8, the open-source Google JavaScript engine written in C++ that powers both Chrome and other Chromium-based browsers* is an especially attractive target for attackers.

A type confusion vulnerability let the exploit to allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

“Access to bug details and links may be kept restricted until a majority of users are updated with a fix.”

“We will also retain restrictions if the bug exists in a third-party library that other projects similarly depend on, but haven’t yet fixed.

“Google is aware that an exploit for CVE-2022-4262 exists in the wild.” Google Stated.

Zero-days Fixed In 2022

Here below we have mentioned all the zero-day vulnerabilities that are detected and fixed in 2022:-

Update now

Upon checking our systems for available updates, we immediately detected this update and it was immediately distributed to our systems. 

So, if you want to update your Chrome too then follow the simple steps that we have mentioned below:-

  • First of all, you have to select the Chrome menu.
  • Then select the Help option.
  • After that, you have to select the About Google Chrome option.
  • Now, wait for a few seconds, as Chrome will now automatically detect and download if there is any update available.

Moreover, Google has strongly recommended all users to immediately update their chrome in order to prevent any exploitation in the wild.

Secure Web Gateway – Web Filter Rules, Activity Tracking & Malware Protection – Download Free E-Book

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

I-O DATA Routers Command Injection Vulnerabilities Actively Exploited in Attacks

I-O DATA DEVICE, INC. has announced that several critical vulnerabilities in their UD-LT1 and...

ChatGPT Next Web Vulnerability Let Attackers Exploit Endpoint to Perform SSRF

Researchers released a detailed report on a significant security vulnerability named CVE-2023-49785, affecting the...

Cisco NX-OS Vulnerability Allows Attackers to Bypass Image Signature Verification

A critical vulnerability has been identified in the bootloader of Cisco NX-OS Software, potentially...

Deloitte UK Hacked – Brain Cipher Group Claim to Have Stolen 1 TB of Data

Brain Cipher has claimed to have breached Deloitte UK and exfiltrated over 1 terabyte...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

I-O DATA Routers Command Injection Vulnerabilities Actively Exploited in Attacks

I-O DATA DEVICE, INC. has announced that several critical vulnerabilities in their UD-LT1 and...

ChatGPT Next Web Vulnerability Let Attackers Exploit Endpoint to Perform SSRF

Researchers released a detailed report on a significant security vulnerability named CVE-2023-49785, affecting the...

Cisco NX-OS Vulnerability Allows Attackers to Bypass Image Signature Verification

A critical vulnerability has been identified in the bootloader of Cisco NX-OS Software, potentially...