CVE-2022-1096highunder attackCWE-843

CVE-2022-1096: high-severity vulnerability in Google Chrome

Published · Updated

76Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 24%
from disclosure to weapon0 days
Published on NVDJul 22
1st PoCMar 29
CISA KEVMar 28
exploitation probability
24%top 2% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
Action required by CISAfederal deadline: 2022-04-18

Apply updates per vendor instructions.

In short

Google Chrome's V8 engine confused different data types in memory, allowing attackers to corrupt the heap through a malicious webpage. This could lead to crashes or potentially execute arbitrary code.

Technical detail

Type confusion vulnerability in V8's type system allows remote attackers to corrupt heap memory via specially crafted HTML. Exploitation requires user interaction (visiting a malicious page) and results in heap corruption with potential code execution impact.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Google · Chrome
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.