Coming Soon...

Q-CERT website is currently under maintenance. We should be back shortly. Thank you for yor patience.

Zero-Day Vulnerability in Google Chrome

Issued: 
Sunday, 17 April, 2022
Last Revision: 
Sunday, 17 April, 2022
Vendor: 
Product: 
Summary: 

Google has released Chrome version 100.0.4896.127 to resolve a vulnerability for which a public exploit code already exists.  The security issue is described as a “Type Confusion bug” and is tagged as CVE-20221364. It is rated as high-severity.

 

The most common outcome of type confusion flaw is browser crashes when read or written memory does not match the bounds of the buffer. Attackers can also exploit the said vulnerability to execute arbitrary code. 

 

CVE/Vulnerability

Description 

 

CVSS3.0 Score

CVE-2022-1364

 Type Confusion in V8

 

n/a

 

Table 1: Vulnerability details 

 

 

CVE/Vulnerability

    Affected Product(s)

CVE-2022-1364

Google Chrome versions prior to 100.0.4896.127

 

              

                                                                                        Table 2: Vulnerable versions                                  

 

 

Recommendation: 

Organizers are encouraged to apply the stable channel 100.0.4896.127 provided by Google to vulnerable systems immediately. This is applicable to Windows, Mac and Linux platform.