CERT-In Vulnerability Note
CIVN-2022-0418
Remote code execution vulnerability in Google Chrome
Original Issue Date:November 01, 2022
Severity Rating: HIGH
Software Affected
- Google Chrome versions prior to 107.0.5304.87 for Mac and Linux
- Google Chrome versions prior to 107.0.5304.87/.88 for Windows
Overview
A vulnerability has been reported in Google Chrome which could allow a remote attacker to execute arbitrary code on the targeted system.
Description
This vulnerability exists in Google Chrome due to a type confusion error within the V8 engine in Google Chrome . A remote attacker could exploit this vulnerability by sending a specially crafted request on the targeted system. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the targeted system.
Note: This vulnerability (CVE-2022-3723) is being exploited in the wild. Users are advised to apply patches urgently.
Solution
Apply appropriate updates as mentioned by vendor.
https://chromereleases.googleblog.com/2022/10/stable-channel-update-for-desktop_27.html
Vendor Information
Google Chrome
https://chromereleases.googleblog.com/2022/10/stable-channel-update-for-desktop_27.html
References
Google Chrome
https://chromereleases.googleblog.com/2022/10/stable-channel-update-for-desktop_27.html
CVE Name
CVE-2022-3723
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|