HIGH

CVE-2022-3723

Google Chrome 2022-11-01 CVSS v3.1
CVSS
8.8
KEV

Description

Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Summary dbcve.org

This is a type confusion vulnerability in the V8 JavaScript engine used by Google Chrome. The flaw allows a remote attacker to craft a malicious HTML page that triggers incorrect type handling in V8, potentially leading to heap corruption and arbitrary code execution.

Mitigation

Update Google Chrome to version 107.0.5304.87 or later to apply the vendor patch. Ensure automatic updates are enabled for future security patches.

Weakness (CWE)

CWE-843 Type Confusion

EPSS Score

7.92%
Probability of exploitation in next 30 days
94.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE