Threat Advisory

Google fixes fifth Chrome zero-day bug exploited this year

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

Google has released a security update for the Chrome browser that addresses close to a dozen vulnerabilities, including a zero-day flaw that is being exploited in the wild. The security update is currently rolling out for Windows, Mac and Linux. Users who have automatic updates turned on should receive it in the coming days/weeks. Google doesn’t typically provide many technical details about the zero-day vulnerabilities they fix until a large number of Chrome users have applied the security update.[/subscribe_to_unlock_form]

Summary:

Google has released a security update for the Chrome browser that addresses close to a dozen vulnerabilities, including a zero-day flaw that is being exploited in the wild. The security update is currently rolling out for Windows, Mac and Linux. Users who have automatic updates turned on should receive it in the coming days/weeks. Google doesn’t typically provide many technical details about the zero-day vulnerabilities they fix until a large number of Chrome users have applied the security update.[emaillocker id="1283"]

The most recent one is tracked as CVE-2022-2856 and it is described as a high-severity security issue due to insufficient validation of untrusted input in Intents, a feature that enables launching applications and web services directly from a web page. Bad input validation in software can serve as a pathway to overriding protections or exceeding the scope of the intended functionality, potentially leading to buffer overflow, directory traversal, SQL injection, cross-site scripting, null byte injection, and more.

References:

The following reports contain further technical details:

https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_16.html

[/emaillocker]
crossmenu