Vulnerability record · CVE-2022-1096 · published 23 July 2022
CVE-2022-1096: Google Chrome V8 type confusion enables heap corruption
Google · Chrome
Google Chrome before 99.0.4844.84 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and potentially corrupt the heap, which matters because Chrome is widely deployed and the flaw was exploited in the wild.
Description
Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityKnown-exploited (CISA KEV) remote code execution-class flaw in a ubiquitous browser, though it requires user interaction and a patch has long been available.
What it is
Google Chrome before 99.0.4844.84 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and potentially corrupt the heap, which matters because Chrome is widely deployed and the flaw was exploited in the wild.
Impact
A remote attacker can potentially achieve heap corruption in the browser process, which can lead to code execution or a crash. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network by loading a crafted HTML page; no privileges are required but user interaction (visiting the page) is needed per the CVSS vector. No authentication is required.
Exploitation
Listed in CISA KEV with a 2022-04-18 remediation due date, indicating known exploitation. EPSS 30-day probability is 0.24205 (97.7th percentile), and references include vendor advisories and a US Government resource.
What to do
- Update Chrome to 99.0.4844.84 or later per the vendor release notes.
- Apply the equivalent Chromium/Electron and downstream (e.g. Gentoo GLSA 202208-25) updates where applicable.
- Enforce browser auto-update and verify version compliance across managed endpoints.
- Restrict or monitor browsing to untrusted sites where feasible until patching is complete.
Detection
- Monitor for Chrome renderer crashes or abnormal heap-related crash reports that cluster after visits to untrusted pages.
- Hunt proxy and DNS logs for known exploit-hosting domains tied to this CVE.
- Track endpoint Chrome version inventory to find hosts still below 99.0.4844.84.
- Review EDR telemetry for suspicious child processes or memory behavior originating from the browser.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-1096 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Google Chromium V8 Type Confusion Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_25.html | Release NotesVendor Advisory |
| https://crbug.com/1309225 | Permissions RequiredVendor Advisory |
| https://security.gentoo.org/glsa/202208-25 | Third Party Advisory |
| https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_25.html | Release NotesVendor Advisory |
| https://crbug.com/1309225 | Permissions RequiredVendor Advisory |
| https://security.gentoo.org/glsa/202208-25 | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-1096 | US Government Resource |
Track CVE-2022-1096 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-1096), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.