CVE-2022-2294 - Heap buffer overflow in WebRTC.CVE-2022-0609 - Use-after-free in Animation.It's also the ninth zero-day flaw attackers have exploited in the wild in 2022. Google acknowledged active exploitation of the vulnerability but stopped short of sharing additional specifics to prevent further abuse.ĬVE-2022-4262 is the fourth actively exploited type confusion flaw in Chrome that Google has addressed since the start of the year. Type confusion vulnerabilities could be weaponized by threat actors to perform out-of-bounds memory access, or lead to a crash and arbitrary code execution.Īccording to the NIST's National Vulnerability Database, the flaw permits a "remote attacker to potentially exploit heap corruption via a crafted HTML page." Clement Lecigne of Google's Threat Analysis Group (TAG) has been credited with reporting the issue on November 29, 2022. The high-severity flaw, tracked as CVE-2022-4262, concerns a type confusion bug in the V8 JavaScript engine. Search giant Google on Friday released an out-of-band security update to fix a new actively exploited zero-day flaw in its Chrome web browser.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |