Google Chrome Security Updates-28 September 2022

Google has released an updated Chrome version (106.0.5249.61/62) for Windows and (106.0.5249.61) for Mac and Linux to fix multiple vulnerabilities. The remote attacker could exploit some of these vulnerabilities to take control of the affected system.

The severity of the addressed vulnerabilities could allow the remote attacker to execute arbitrary code, bypass security restrictions by persuading the victim to visit a specially crafted webpage or cause a denial of service condition on the affected system.

Sample of the addressed vulnerabilities:

1. Google Chrome CSS code execution (CVE-2022-3304):

• CVSS: 8.8

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: None

• User Interaction: Required

• Consequences: Gain Access

2. Google Chrome Survey code execution (CVE-2022-3305):

• CVSS: 8.8

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: None

• User Interaction: Required

• Consequences: Gain Access

Vulnerabilities

• CVE-2022-3201
• CVE-2022-3304
• CVE-2022-3305
• CVE-2022-3306
• CVE-2022-3307
• CVE-2022-3311
• CVE-2022-3312
• CVE-2022-3313
• CVE-2022-3314
• CVE-2022-3315
• CVE-2022-3308
• CVE-2022-3309
• CVE-2022-3310
• CVE-2022-3316
• CVE-2022-3317
• CVE-2022-3318

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Google Chrome releases

References