THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Thursday, December 01, 2022
Google has patched a zero-day vulnerability in its Chrome browser.
FREMONT, CA: Google has fixed the seventh such vulnerability of this year in its Chrome browser. According to Google (NASDAQ: GOOGL), the flaw resulted from a heap buffer overflow in the GPU. These flaws could give hackers access to the application's heap and give them the ability to change the data that the Chrome Browser outputs.
Exploiting buffer overflow vulnerabilities may also result in widespread data corruption within the application or manipulation of the internal workings of the Chrome browser. Despite there not yet being a particular CVSSv3 score, it has been given a severity level of high. According to the frequently used metric, high severity ratings often correspond to a score between 7.0 and 8.9, which is the second-highest severity category.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
The latest stable channel version of Google Chrome was available for Windows, macOS, and Linux. Google awarded the vulnerability a CVE for vulnerability monitoring and management (CVE-2022-4135).
Google stated that until more people have had a chance to install the update, it will withhold more specific information about the problem. Additionally, it won't divulge any additional information if the Google Chrome team discovers the problem in a third-party library that other applications rely on, for example, at least until that library also provides a fix.
The flaw was found by a security engineer with Google's Threat Analysis Group, a security unit primarily tasked with thwarting government-sponsored hacking operations. Google made no mention of the flaw being actively exploited in the wild.
The second zero-day resulting from a heap buffer overflow, CVE-2022-4135, is the eighth zero-day vulnerability discovered in Google Chrome since the year 2022 began.
Three of the eight zero-day vulnerabilities affecting the most widely used browser in the world were brought on by flaws in the open-source and proprietary JavaScript V8 engine developed by Google.
Microsoft Edge, Opera, Vivaldi, and other popular browsers operating on Chromium were also at risk because they used Google's V8 engine.
More in News