HIGH
CVE-2022-1364
CVSS
8.8
KEV
Description
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Summary dbcve.org
Type confusion vulnerability in Google Chrome's V8 Turbofan JavaScript optimizing compiler allows a remote attacker to exploit heap corruption via a specially crafted HTML page. The flaw exists in the type inference mechanism of the Turbofan compiler, where incorrect type assumptions can lead to memory corruption.
Mitigation
Update Google Chrome to version 100.0.4896.127 or later to patch the V8 type confusion vulnerability. Organizations should ensure browsers are updated through their patch management processes.
Weakness (CWE)
CWE-843
Type Confusion
EPSS Score
13.72%
Probability of exploitation in next 30 days
96.4th percentile
References
https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_14.html
Release Notes, Vendor Advisory
https://crbug.com/1315901
Exploit, Issue Tracking, Patch, Vendor Advisory
https://security.gentoo.org/glsa/202208-25
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-1364
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.