Description

Google, IT giant, has released Chrome 108.0.5359.94/.95 for Windows, Mac, and Linux users to fix a ninth zero-day vulnerability that is exploited in the wild. According to a security advisory published on 2nd December 2022, Google is aware of the CVE-2022-4262 which is being exploited in the wild. This zero-day vulnerability (CVE-2022-4262), which has been reported by a threat analyst Clement Lecigne, is caused due to a high-severity type confusion weakness in Google's Chrome V8 JavaScript engine. However, even though type confusion security flaws generally lead to browser crashes after successful exploitation by reading or writing memory out of buffer bounds, attackers can also exploit them for arbitrary code execution. In addition, Google has acknowledged detecting attacks exploiting this zero-day, but it has not provided any technical details or information as many users are yet to apply the fixes. Google also claimed that they will retain restrictions if the bug exists in a third-party library that other projects similarly rely on, but haven't yet fixed.