Google has released Chrome 105.0.5195.102 for Windows, Mac, and Linux, which addresses a critical vulnerability (CVE-2022-3075) that is already being exploited by attackers (0-day). The issue has also been resolved in the 104.0.5112.114 release of the separately maintained Extended Stable branch.
Details are not yet disclosed, but it has been reported that the 0-day vulnerability is due to improper data validation in the Mojo IPC library. Judging by the code of the added change, the problem stems from a lack of type checking for the message passed in the IPC response against the value specified in the request.
Source: opennet.ru
