CVE-2022-4262 is a high-severity type confusion vulnerability in Google Chrome's V8 JavaScript engine, affecting versions prior to 108.0.5359.94. This flaw allows a remote attacker to achieve heap corruption and potentially execute arbitrary code by enticing a user to visit a specially crafted HTML page. With a CVSS score of 8.8, it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. Notably, this vulnerability is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, and has garnered substantial community discussion and media coverage, despite no public exploit code being readily available in common databases.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 108.0.5359.94CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.