Chrome update 105.0.5195.102 fixing 0-day vulnerability

Google has released Chrome update 105.0.5195.102 for Windows, Mac and Linux, which fixes a serious vulnerability (CVE-2022-3075) already used by attackers to carry out attacks (0-day). The issue is also fixed in release 104.0.5112.114 of the separately maintained Extended Stable branch.

Details have not yet been disclosed, it is only reported that the 0-day vulnerability is caused by incorrect data validation in the Mojo IPC library. Judging by the code of the added change, the problem is caused by the lack of a check that the type of the message sent in the IPC response matches the value specified in the request.

Source: opennet.ru

Add a comment