Originally published 07/14/2022
Google Chrome
On July 4, Google quietly released a stable channel update for Google Chrome to patch an actively exploited zero-day vulnerability. This is the fourth flaw Google has released for Google Chrome this year.
Chrome 103 (103.0.5060.71 for Android and 103.0.5060.114 for Windows and Mac) fixes a heap buffer overflow flaw in WebRTC. WebRTC is the engine that gives the browser its real-time communications capability.[1] The vulnerability, given the moniker CVE-2022-2294 and reported by Jan Vojtesek from the Avast Threat Intelligence team, is described as a buffer overflow, “where the buffer that can be overwritten is allocated in the heap portion of memory.”[1]
Google did not reveal any specific details about the vulnerability, but it recommended that users upgrade their Google Chrome browsers. Because there are so few known details about the flaw, the most feasible protection for users is to upgrade their browsers. Fortunately, Google Chrome updates are pushed automatically, so most users will be protected once an update is available.[1]
Buffer overflows can lead to crashes and other attacks that make the affected program unavailable, such as causing it to enter an infinite loop. Attackers can exploit the attack by using the crash to execute arbitrary code, often outside the scope of the program’s security policy.[1]
Along with fixing the zero-day buffer overflow flaw, the fix also patches a confusion flaw in the V8 JavaScript engine (CVE-2022-2295), which was reported on June 16th by researchers at S.S.L.[1] This is the third flaw of this nature found in the open-source engine used by Google Chrome and Chromium-based web browsers, and it has been patched this year. In March, a different type-confusion issue in the V8 JavaScript engine (CVE-2022-1096) required a hasty patch from Google. And in April, Google patched another type-confusion flaw (CVE-2022-1364), which affected Google Chrome’s use of V8, and that attackers had already pounced on.[1]
Another flaw patched in the July 4 Google Chrome update is a use-after-free flaw in Chrome OS Shell, which was reported by Khalil Zhani on May 19th and was given the moniker CVE-2022-2296, according to Google. Prior to patching the Chrome V8 JavaScript engine flaws in March and April, Google patched a zero-day use-after-free flaw in Chrome’s Animation component (CVE-2022-0609) in February that was under attack.[1]
Because the specific details of this flaw have not been announced, there are currently no MITRE ATT&CK Entries associated with it.
Because the specific details of this flaw have not been announced, there are currently no IOCs associated with this flaw.
(1) Montalbano, Elizabeth. “Google Patches Actively Exploited Chrome Bug.” Threatpost English Global, July 5, 2022. https://threatpost.com/actively-exploited-chrome-bug/180118/.
Contributing Security Analysts: Dorian Pope, Sreten Dedic, EJ Bulut, Tural Hagverdiyev, Uday Bilakhiya.