Junglewise Threat Intelligence

CVE-2022-4262: Google Chromium V8 Type Confusion Vulnerability

CVE-2022-4262 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-12-05

Technologies: Google Chromium V8, Microsoft Edge, Google Chrome. Vendors: Google, Opera, Microsoft.

Executive brief

A type confusion vulnerability in the Google Chromium V8 engine allows a remote attacker to exploit heap corruption via a specially crafted HTML page. This flaw was reported as being exploited in the wild at the time of discovery.

Affected products

  • Google Chrome prior to 108.0.5359.94
  • Google V8 Engine
  • Microsoft Edge
  • Opera Opera

Timeline

  • 2022-12-02: disclosed: NVD Published Date
  • 2022-12-05: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-12-02: patched: Fixed in Chrome version 108.0.5359.94
  • 2022-12-05: exploited: Reported as exploited in the wild in the advisory

Related threats