Executive brief
A type confusion vulnerability exists in the V8 engine of Google Chromium. A remote attacker can exploit this via a crafted HTML page to cause heap corruption, potentially leading to arbitrary code execution.
Affected products
- Google Chrome prior to 107.0.5304.87
- Google Chromium
- Microsoft Edge
- Opera Software Opera
Timeline
- 2022-10-28: disclosed
- 2022-10-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-10-28: exploited: Reported as exploited in the wild at time of publication.
- 2022-11-01: advisory: NVD Published Date