Project Hyphae
Search

Operation AppleJeus & Other Attackers Are Putting The Squeeze on Google Chrome Zero Day

Share This Post

A Google Chrome remote code execution (RCE) zero-day vulnerability is being actively exploited by at least two threat groups, according to Google. Operation AppleJeus and Operation Dream Job have been exploiting this flaw since as early as January 4, 2022.

Originally discovered by North Korean threat actors, the vulnerability allows threat actors to reference memory addresses after they have been freed by Chrome in order to crash the application, use unexpected values, or execute arbitrary code remotely.

Tracked as CVE-2022-1096, a high-priority security patch has been released to update Google Chrome to version 99.0.4844.84 in response. All of the world’s 3,200,000,000 Chrome users are advised to ensure their browsers are updated as a matter of urgency.

iTechPost Summary: https://www.itechpost.com/articles/109748/20220328/google-chrome-security-update-cve-2022-1096-high-severity-zero.htm



Reach out to our incident response team for help

More To Explore

Information Security News 4-22-2024

Cisco Duo Warns Third-Party Data Breach Exposed SMS MFA Logs Article Link: https://www.bleepingcomputer.com/news/security/cisco-duo-warns-third-party-data-breach-exposed-sms-mfa-logs/ Notorious Russian Hacking Unit Linked to Breach of Texas Water Facility Article

Information Security News 4-15-2024

Roku Disclosed a Security Incident Impacting 576,000 Accounts Article Link: https://securityaffairs.com/161765/data-breach/roku-second-data-breach.html FBI Warns of Massive Wave of Road Toll SMS Phishing Attacks Article Link: https://www.bleepingcomputer.com/news/security/fbi-warns-of-massive-wave-of-road-toll-sms-phishing-attacks/

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.