HIGH
CVE-2022-3723
CVSS
8.8
KEV
Description
Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Summary dbcve.org
This is a type confusion vulnerability in the V8 JavaScript engine used by Google Chrome. The flaw allows a remote attacker to craft a malicious HTML page that triggers incorrect type handling in V8, potentially leading to heap corruption and arbitrary code execution.
Mitigation
Update Google Chrome to version 107.0.5304.87 or later to apply the vendor patch. Ensure automatic updates are enabled for future security patches.
Weakness (CWE)
CWE-843
Type Confusion
EPSS Score
7.92%
Probability of exploitation in next 30 days
94.5th percentile
References
https://chromereleases.googleblog.com/2022/10/stable-channel-update-for-desktop_27.html
Release Notes, Vendor Advisory
https://crbug.com/1378239
Permissions Required
https://security.gentoo.org/glsa/202305-10
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-3723
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.