← Back to BrewedIntel
vulnerabilitycriticalRemote Code ExecutionZero-Day Vulnerability

Aug 18, 2022 • Elizabeth Montalbano

Google Patches Chrome’s Fifth Zero-Day of the Year

Google has released an emergency security update for Chrome, addressing the browser's fifth zero-day vulnerability of the year. The flaw, an insufficient...

Source
Threatpost
Category
vulnerability
Severity
critical

Executive Summary

Google has released an emergency security update for Chrome, addressing the browser's fifth zero-day vulnerability of the year. The flaw, an insufficient input validation issue, is being actively exploited in the wild and could allow attackers to achieve arbitrary code execution on affected systems. This vulnerability is one of 11 security flaws patched in this update. Users and organizations are strongly advised to update Chrome immediately to the latest version to mitigate the risk of compromise. This marks a significant escalation in browser-based attack activity, highlighting the continued targeting of widely-deployed software by threat actors.

Summary

An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.

Published Analysis

Google has released an emergency security update for Chrome, addressing the browser's fifth zero-day vulnerability of the year. The flaw, an insufficient input validation issue, is being actively exploited in the wild and could allow attackers to achieve arbitrary code execution on affected systems. This vulnerability is one of 11 security flaws patched in this update. Users and organizations are strongly advised to update Chrome immediately to the latest version to mitigate the risk of compromise. This marks a significant escalation in browser-based attack activity, highlighting the continued targeting of widely-deployed software by threat actors. An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack. An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.