Google Chrome Security Updates 02 October 2022

Google has released an updated Chrome version (106.0.5249.91) for Windows, Mac, and Linux to fix multiple vulnerabilities. The remote attacker could exploit these vulnerabilities to take control of the affected system.

The severity of the addressed vulnerabilities could allow the remote attacker to execute arbitrary code on the affected system by persuading the victim to visit a specially crafted web page.
1. Google Chrome v8 Code Execution (CVE-2022-3373):
• CVSS: 8.8
• Attack Vector: Network
• Attack Complexity: Low
• Privileges Required: None
• User Interaction: Required
• Consequences: Gain Access
2. Google Chrome Custom Elements Code Execution (CVE-2022-3370):
• CVSS: 8.8
• Attack Vector: Network
• Attack Complexity: Low
• Privileges Required: None
• User Interaction: Required
• Consequences: Gain Access

Vulnerabilities
  • CVE-2022-3370
  • CVE-2022-3373
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Google Security Updates

References