Skip to content
COOEY

EXPOSURES › CVE-2022-1096

CVE-2022-1096

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-28 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-1096 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 exploited-in-wildunpatchedrce

A type confusion vulnerability in Google's Chromium V8 engine allowed remote attackers to exploit heap corruption via crafted HTML pages.

This vulnerability affected multiple Chromium-based browsers, enabling remote code execution through heap corruption. DIB organizations must ensure their browsers are patched promptly, as unpatched instances could lead to data breaches or ransomware entry. The vulnerability was actively exploited in the wild, highlighting the risk of relying on unpatched software.

Shame score — The vulnerability was actively exploited in the wild, indicating a failure to patch known issues before exploitation, which is a severe compliance and security failure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized