Google Fixes 5th Actively Exploring Zero-Day Bug within Chrome For This Year

Published:

At present, Google has only described the flaw as being a severe danger.

Prepare to patch. Google has found hackers exploiting an previously undiscovered Chrome browser vulnerability.

The company has referenced its “zero-day exploit” in the latest updates for Chrome that were made available on Tuesday. Google identified the vulnerability of high severity by enlisting the help of security experts from its own team.

The flaw has been assigned the codename CVE-2022-2856(Opens in an entirely new window) However, the company remains mum about the specifics. At present, Google has only described the flaw as involving “insufficient validation of untrusted input in Intents.”

These intents(Opens in the new window) could permit a web site to connect to and run a third-party application over the browser session. There’s a great chance that hackers are using the zero-day vulnerability to distribute malware via a web page or via phishing emails.

CVE-2022-3056 marks the fifth time in the year that Google has patched a widely exploited flaw within the Chrome browser. In the month of March, Google patched a fourth vulnerability that security researchers from Avast believe is linked with an Israeli spyware firm known as Candiru and its efforts to track journalists.

In march, Google acknowledged(Opens with a brand new tab) that it had seen an increase in exploited zero-day weaknesses throughout the world, and particularly in Chrome. Chrome browser.

The company claims it is due to security companies and Google are getting better at identifying zero-day security threats that target users. In the same way hackers of the elite are looking for ways to attack Chrome because of its popularity.

Another reason can be the fact the fact that “browsers increasingly mirror the complexity of operating systems–providing access to your peripherals, filesystem, 3D rendering, GPUs–and more complexity means more bugs,” Google declares.

The patch for CVE-2022-3056 is expected to start rolling out to Chrome browser to Windows, macOS, and Linux devices in the next days and weeks using Chrome Version 104.0.5112.101/102. You can determine the version of Chrome you’re using by visiting your About Google Chrome function. This function will automatically start downloading the most recent Chrome version when it’s available.

Related articles

Recent articles

[tds_leads title_text="Subscribe" input_placeholder="Your email address" btn_horiz_align="content-horiz-center" pp_checkbox="yes" pp_msg="SSd2ZSUyMHJlYWQlMjBhbmQlMjBhY2NlcHQlMjB0aGUlMjAlM0NhJTIwaHJlZiUzRCUyMiUyMyUyMiUzRVByaXZhY3klMjBQb2xpY3klM0MlMkZhJTNFLg=="]