CVE-2022-1096: high-severity vulnerability in Google Chrome
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
Google Chrome's V8 engine confused different data types in memory, allowing attackers to corrupt the heap through a malicious webpage. This could lead to crashes or potentially execute arbitrary code.
Type confusion vulnerability in V8's type system allows remote attackers to corrupt heap memory via specially crafted HTML. Exploitation requires user interaction (visiting a malicious page) and results in heap corruption with potential code execution impact.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.