Vulnerability record · CVE-2022-1364 · published 26 July 2022
CVE-2022-1364: Google Chrome V8 Turbofan type confusion allows heap corruption
Google · Chrome
Google Chrome before 100.0.4896.127 contains a type confusion flaw in the V8 Turbofan compiler. A crafted HTML page can trigger the confusion and potentially corrupt the heap, making this a browser-engine memory safety issue that matters because Chrome is widely deployed and the flaw was exploited in the wild.
Description
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is a remotely reachable browser engine memory corruption issue with confirmed exploitation in CISA KEV, though it requires user interaction and a patch has long been available.
What it is
Google Chrome before 100.0.4896.127 contains a type confusion flaw in the V8 Turbofan compiler. A crafted HTML page can trigger the confusion and potentially corrupt the heap, making this a browser-engine memory safety issue that matters because Chrome is widely deployed and the flaw was exploited in the wild.
Impact
An attacker who gets the page rendered can potentially achieve heap corruption, which in a browser engine typically opens the path to code execution in the renderer process. The record does not state the exact post-exploitation outcome beyond potential heap corruption.
Attack surface
Reached over the network by loading a crafted HTML page; the CVSS vector shows no privileges required but user interaction required, so a victim must open or be directed to the page. No authentication is needed.
Exploitation
Listed in CISA KEV with a 2022-04-15 addition and 2022-05-06 remediation due date, and references are tagged Exploit, indicating known exploitation. EPSS 30-day probability is 0.1372 (96.3rd percentile), so exploitation is plausible and observed rather than theoretical.
What to do
- Update Chrome to 100.0.4896.127 or later per the vendor release notes, and verify version compliance across managed endpoints.
- Apply the referenced Gentoo GLSA update if Chromium is installed from Gentoo packages.
- Enforce automatic browser updates and block or prompt on outdated Chrome versions.
- Reduce exposure by restricting untrusted web browsing and isolating high-risk browsing in a separate environment.
- Track CISA KEV remediation deadlines and confirm closure for internet-facing browser fleets.
Detection
- Monitor for Chrome renderer crashes or abnormal process terminations that could indicate type confusion exploitation attempts.
- Hunt proxy and DNS logs for access to known malicious or exploit-hosting domains serving crafted HTML pages.
- Check endpoint telemetry for suspicious child processes spawned from Chrome renderer processes.
- Audit installed Chrome versions against 100.0.4896.127 to find unpatched hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-1364 to the Known Exploited Vulnerabilities catalog on 15 April 2022 as "Google Chromium V8 Type Confusion Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 6 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_14.html | Release NotesVendor Advisory |
| https://crbug.com/1315901 | ExploitIssue TrackingPatchVendor Advisory |
| https://security.gentoo.org/glsa/202208-25 | Third Party Advisory |
| https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_14.html | Release NotesVendor Advisory |
| https://crbug.com/1315901 | ExploitIssue TrackingPatchVendor Advisory |
| https://security.gentoo.org/glsa/202208-25 | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-1364 | US Government Resource |
Track CVE-2022-1364 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-1364), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.