VDB
CVE-2022-1096
CVE-2022-1096
PUBLISHED
CVSS 8.8 HIGH
Reported by Chrome · Published July 22, 2022
Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Risk Scores
CVSS v3.1
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chrome | unspecified | |
| alpine | qt5-qtwebengine | 0, 0, 0 |
| alpine | chromium | 0, 0, 0 |
| Chrome | unspecified |
Timeline
- Jan 20, 1970 VulnCheck XDB Entry
- Jan 20, 1970 VulnCheck XDB Entry
- Jan 20, 1970 VulnCheck XDB Entry
- Jan 20, 1970 VulnCheck XDB Entry
- Jan 20, 1970 VulnCheck XDB Entry
- Jan 21, 1970 VulnCheck XDB Entry
- Jun 8, 2021 VulnCheck KEV Exploitation
- Mar 25, 2022 PoC Published
- Mar 28, 2022 CISA KEV Added
- Apr 4, 2022 CVE Published
- Jul 23, 2022 EPSS Score
- Aug 15, 2022 VulnCheck KEV Exploitation
References
- x_refsource_MISC
- x_refsource_MISC
- GLSA-202208-25 vendor-advisoryx_refsource_GENTOO
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-1096 url