HIGH
CVE-2022-1096
CVSS
8.8
KEV
Description
Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Summary dbcve.org
Type confusion vulnerability in Google Chrome's V8 JavaScript engine (versions prior to 99.0.4844.84) allows a remote attacker to potentially exploit heap corruption via a malicious crafted HTML page. This client-side vulnerability stems from improper type handling in the V8 engine that can be triggered when a user visits a specially crafted website.
Mitigation
Update Google Chrome to version 99.0.4844.84 or later. Organizations should deploy the browser update through their standard patch management processes and verify completion across all managed endpoints.
Weakness (CWE)
CWE-843
Type Confusion
EPSS Score
24.21%
Probability of exploitation in next 30 days
97.8th percentile
References
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_25.html
Release Notes, Vendor Advisory
https://crbug.com/1309225
Permissions Required, Vendor Advisory
https://security.gentoo.org/glsa/202208-25
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-1096
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.