Google released an emergency update for the Chrome 107 to address an actively exploited zero-day vulnerability tracked as CVE-2022-3723.
The CVE-2022-3723 flaw is a type confusion issue that resides in the Chrome V8 Javascript engine.
The flaw has been reported by Jan Vojtěšek, Milánek, and Przemek Gmerek of Avast on October 25, 2022.
“Google is aware of reports that an exploit for CVE-2022-3723 exists in the wild,” reads the advisory published by Google. “Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.“
This is the seventh Chrome zero-day fixed by Google this year, below is the full list:
Google did not disclose details about the attack and did not attribute them to a specific threat actor.
At this time is is unclear if the attacks exploiting the CVE-2022-3723 flaws are part of the operation detailed by Avast and associated with the Candiru‘s surveillance activity.
Follow me on Twitter: @securityaffairs and Facebook
[adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Log4Shell)
[adrotate banner=”5″]
[adrotate banner=”13″]