Coming Soon...

Q-CERT website is currently under maintenance. We should be back shortly. Thank you for yor patience.

Actively exploited zero-day vulnerability in Google Chrome

Issued: 
Wednesday, 16 February, 2022
Last Revision: 
Wednesday, 16 February, 2022
Vendor: 
Product: 
Severity Level: 
Summary: 

A Google Chrome update has been released that includes eleven security fixes, one of which has reportedly been exploited in the wild.

 

Actively exploited vulnerability has been assigned the number CVE-2022-0609, as a use-after-free flaw in Chrome's Animation component. This type of issue can cause a wide range of problems, from data corruption to arbitrary code execution on affected computers. The browser's security sandbox can likewise be bypassed using such weaknesses.

 

According to its security update, Google is aware that an exploit for CVE-2022-0609 exists in the wild.

 

CVE/Vulnerability

Description 

CVSS3.0 Score

CVE-2022-0609

 Use-after-free vulnerability

n/a

 

 

Table 1: Vulnerability details 

 

 

 

CVE/Vulnerability

Affected Product(s)

CVE-2022-0609

Chrome web browser prior to  98.0.4758.102 for Windows, Mac and Linux

 

 

                                                                                            Table 2: Vulnerable versions                                  

 

 

Recommendation: 

Because the zero day has now been exploited, it is strongly recommended  to upgrade to the stable channel 98.0.4758.102 for Windows, macOS and Linux to fix the exploited vulnerability as well as ten other reported security issues in this release.