Chrome's first zero-day bug for 2022 is reportedly being exploited

By

Don't wait for the auto-update.

Google has found a zero-day in Chrome for Windows, Mac, and Linux, which it believes may be under exploit.

Chrome's first zero-day bug for 2022 is reportedly being exploited

The company released a patch that fixes a number of security vulnerabilities, notably CVE-2022-0609 for which Google’s advisory says it "is aware of reports that an exploit... exists in the wild”.

The CVE-2022-0609 bug is a use-after-free in Chrome’s Animation component.

The other bugs are a use-after-free in the Webstore API (CVE-2022-0605), one in the Angle graphics engine (CVE-2022-0606), another in Chrome’s GPU process (CVE-2022-0607), an integer overflow in the Mojo sandboxing process (CVE-2022-0608), and a bug in the Gamepad API implementation (CVE-2022-0610).

While Google’s post said Chrome will update itself “over the coming days/weeks”, the browser can be updated from the About Google Chrome menu immediately.

The Animation bug was found by Adam Weidemann and Clément Lecigne of Google's Threat Analysis Group.

The patch brings Chrome’s Stable channel to version 98.0.4758.102.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Woolworths' CSO is Optus-bound

Woolworths' CSO is Optus-bound

Australia's super funds told to assess authentication controls

Australia's super funds told to assess authentication controls

Hackers abuse modified Salesforce app to steal data, extort companies

Hackers abuse modified Salesforce app to steal data, extort companies

The Northern Beaches Women's Shelter hones focus on tech-enabled abuse

The Northern Beaches Women's Shelter hones focus on tech-enabled abuse

Log In

  |  Forgot your password?