Junglewise Threat Intelligence

CVE-2022-1096: Google Chromium V8 Type Confusion Vulnerability

CVE-2022-1096 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-28

Technologies: Google Chromium V8, Google Chrome, Microsoft Edge. Vendors: Google, Opera, Microsoft.

Executive brief

A type confusion vulnerability in the Google Chromium V8 engine allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This flaw impacts multiple Chromium-based browsers including Google Chrome, Microsoft Edge, and Opera.

Affected products

  • Google Chrome prior to 99.0.4844.84
  • Microsoft Edge
  • Opera Opera

Timeline

  • 2022-03-28: disclosed: Published date in advisory
  • 2022-03-28: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-25: patched: Stable channel update for desktop released
  • 2022-03-28: exploited: Reported as exploited in the wild in the advisory and CISA KEV catalog.

Related threats