Security experts have issued an emergency Google Chrome update for its latest version in the light of a zero-day exploit, the ninth one of the year. Clement Lecigne of Google’s TAG disclosed the details regarding the Google Chrome vulnerability.
What’s happening?
Google confirmed the existence of an exploit that hackers could be using against the recently disclosed Chrome zero-day. Tracked as CVE-2022-4262, it is a highly critical type-confusion flaw in Chrome’s V8 JavaScript engine.
What’s the threat?
Hackers exploiting the Chrome vulnerability can execute RCE-based attacks by serving untrusted code from a malicious page, resulting in arbitrary code execution attacks.
Furthermore, the Chrome zero-day could allow a remote attacker to potentially exploit heap corruption via a specially crafted HTML page.
The fix
Google claimed to have addressed the Chome zero-day for different OS platforms with the new Google Chrome update.
It has readied versions 108.0.5359.94 for Mac and Linux and version 108.0.5359.94/.95 for Windows.
However, users may have to wait for a few days/weeks before it reaches them.
What’s more?
Google researchers haven’t shared technical details about the Chrome vulnerability to let users finish their Chrome updates. Else, if shared, hackers would start abusing it.
Besides, the Chrome zero-day has found its place in the CISA’s Known Exploited Vulnerabilities catalog.