CVE-2022-3723: Type Confusion in V8
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Other sources
Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 107.0.5304.87
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3723?
The severity of CVE-2022-3723 is High, with a severity value of 8.8.
How does CVE-2022-3723 affect Google Chromium V8 Engine?
CVE-2022-3723 affects Google Chromium V8 Engine by allowing a remote attacker to potentially exploit heap corruption via a crafted HTML page.
What is the affected version of Google Chrome for CVE-2022-3723?
The affected version of Google Chrome for CVE-2022-3723 is prior to 107.0.5304.87.
How can I fix CVE-2022-3723?
To fix CVE-2022-3723, update Google Chrome to version 107.0.5304.87 or later.
Where can I find more information about CVE-2022-3723?
You can find more information about CVE-2022-3723 on the following references: [Reference 1](https://chromereleases.googleblog.com/2022/10/stable-channel-update-for-desktop_27.html), [Reference 2](https://crbug.com/1378239), [Reference 3](https://security.gentoo.org/glsa/202305-10).