Junglewise Threat Intelligence

CVE-2022-3723: Google Chromium V8 Type Confusion Vulnerability

CVE-2022-3723 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-10-28

Technologies: Google Chromium V8, Microsoft Edge, Opera Software Opera, Google Chrome, Google Chromium. Vendors: Google, Microsoft, Opera Software.

Executive brief

A type confusion vulnerability exists in the V8 engine of Google Chromium. A remote attacker can exploit this via a crafted HTML page to cause heap corruption, potentially leading to arbitrary code execution.

Affected products

  • Google Chrome prior to 107.0.5304.87
  • Google Chromium
  • Microsoft Edge
  • Opera Software Opera

Timeline

  • 2022-10-28: disclosed
  • 2022-10-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-10-28: exploited: Reported as exploited in the wild at time of publication.
  • 2022-11-01: advisory: NVD Published Date

Related threats