Coming Soon...

Q-CERT website is currently under maintenance. We should be back shortly. Thank you for yor patience.

Actively Exploited Vulnerability in Google Chrome

Issued: 
Sunday, 4 September, 2022
Last Revision: 
Sunday, 4 September, 2022
Vendor: 
Severity Level: 
Summary: 

Google has released Chrome version 105.0.5195.102 for Mac, Linux and Windows. This update has been released to addresses the zero-day vulnerability that is exploited in the wild. The exploited vulnerability is tracked as CVE-2022-3075.

 

On the successful exploitation of this vulnerability, attacker can execute arbitrary code, install programs, view, change, or delete data; or create new accounts with full user rights.

 

CVE/Vulnerability

Description 

CVSS3.0 Score

CVE-2022-3075

Insufficient data validation in Mojo

n/a

 

 

Table 1: Vulnerability details 

 

 

CVE/Vulnerability

Affected Product(s)

CVE-2022-3075

Google Chrome versions prior to 105.0.5195.102 (Windows)

Google Chrome versions prior to 105.0.5195.102 (Mac/Linux)

 

 

                                                                                   Table 2: Vulnerable versions 

Recommendation: 

Organizers are encouraged to apply the latest stable channel with necessary testing. This is applicable to  Windows, Mac and Linux platform.   

 

The patches should be applied as soon as they become available to users of Chromium-based browsers like Microsoft Edge, Brave, Opera, and Vivaldi.