CVE-2022-1096 is a critical type confusion vulnerability in Google Chrome's V8 JavaScript engine, affecting all operating systems except iOS. This flaw allows a remote attacker to achieve heap corruption and potentially execute arbitrary code by enticing a user to visit a specially crafted HTML page. With a CVSS score of 8.8 (HIGH), the vulnerability is easily exploitable over the network with low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. Notably, this zero-day vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog and extensive media coverage, despite the absence of public exploit code in Metasploit, Nuclei, or ExploitDB. The high community discussion volume further underscores its significance and the urgency for patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 99.0.4844.84CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.