Junglewise Threat Intelligence

CVE-2022-1364: Google Chromium V8 Type Confusion Vulnerability

CVE-2022-1364 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-04-15

Technologies: Google Chromium V8, Microsoft Edge, Opera Software Opera, Google Chrome. Vendors: Google, Microsoft, Opera Software.

Executive brief

A type confusion vulnerability in the V8 Turbofan engine of Google Chromium allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability was reported as being exploited in the wild at the time of disclosure.

Affected products

  • Google Chrome prior to 100.0.4896.127
  • Microsoft Edge
  • Opera Software Opera

Timeline

  • 2022-04-14: patched: Stable channel update for desktop released (100.0.4896.127)
  • 2022-04-15: disclosed: Initial publication date
  • 2022-04-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-04-15: exploited: Reported as exploited in the wild

Related threats