CISA Warns of New Chrome Zero-Day

Share This Post

On Friday, December 2nd, 2022, Google released updates for Chrome on Android and Desktop (Windows, Mac and Linux). The Desktop update, in particular, contained fixes to combat a new zero-day vulnerability, tracked as CVE-2022-4262. This is Chrome’s ninth patched zero-day of 2022.

On Monday, December 5th, the Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its list of bugs known to be exploited in attacks, though specific technical details have not been shared at this time. CISA is requiring all Federal Civilian Executive Branch (FCEB) agencies to push this patch out by December 26th, three weeks from the announcement, and the Department of Homeland Security cybersecurity agency is strongly urging all U.S. organizations to do the same.

The vulnerability is caused by a high-severity type confusion weakness in the Chromium V8 JavaScript engine. Traditionally, type confusion flaws typically lead to attacks that cause browser crashes caused by reading and writing memory out of buffer bounds, but attackers can exploit them for arbitrary code execution, as well.

Google’s original security advisory can be found here: https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop.html



Reach out to our incident response team for help

More To Explore

Information Security News – 5/12/2025

Microsoft Sets Passkeys Default for New Accounts Article Link: https://thehackernews.com/2025/05/microsoft-sets-passkeys-default-for-new.html Accenture: What We Learned When Our CEO Got Deepfaked Article Link: https://www.computing.co.uk/event/2025/accenture-what-we-learned-when-our-ceo-got-deepfaked Ghost Students Creating

Information Security News – 5/5/2025

Cloudflare Sees a Big Jump in DDoS Attacks Article Link: https://www.bleepingcomputer.com/news/security/cloudflare-mitigates-record-number-of-ddos-attacks-in-2025/ Bring Your Own Computer Trend Gives Cyber Pros Chills, Yet It’s Here to Stay

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.