Google patched 4th Chrome zero-day vulnerability this year

Google patched 4th Chrome zero-day vulnerability this year

Google issued an emergency patch for a critical vulnerability in its Chrome browser which is already exploited in the wild.

Using this bug (CVE-2022-2294), a remote attacker can execute arbitrary code on the target system and compromise it completely. The vulnerability exists due to a boundary error within WebRTC implementation. The attacker can trick the victim to visit a specially crafted website, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

The bug affects both Android and Windows versions of Google’s browser. The issue was addressed in Chrome 103.0.5060.114 for Windows. For now, the update is available through the Stable Desktop channel, but according to the tech giant, the new version will be rolled out to all users in days or weeks.

Google also fixed the vulnerability in Chrome 103 (103.0.5060.71) for Android. The new version will become available on Google Play over the next few days.

As always, Google haven’t shared any details about this zero-day except the fact that it is exploited by hackers. Any information about the attacks is not available either.

This is the fourth zero-day vulnerability in Chrome fixed by Google in 2022. Previously, the tech giant patched zero-day vulnerabilities CVE-2022-1364 (April 14th), CVE-2022-1096 (March 25th) and CVE-2022-0609 (February 14th).

According to recent Google report, half of 2022's zero-days are the variants of zero-day vulnerabilities patched last year.

Back to the list

Latest Posts

Cyber Security Week in Review: June 6, 2025

Cyber Security Week in Review: June 6, 2025

In brief: a critical vBulletin bug is being exploited in the wild, new destructive PathWiper malware targets Ukraine, and more.
6 June 2025
New PathWiper malware targets critical infrastructure in Ukraine

New PathWiper malware targets critical infrastructure in Ukraine

PathWiper shares several characteristics with Sandworm's HermeticWiper, which was used in attacks against Ukraine in 2022.
5 June 2025
US seizes 145 domains linked to BidenCash carding forum

US seizes 145 domains linked to BidenCash carding forum

It is estimated that the operation generated more than $17 million in revenue since launching in March 2022.
5 June 2025