SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Google Fixed Actively Exploited Chrome Zero-Day Vulnerability-Patch Now!

Google Fixed Actively Exploited Chrome Zero-Day Vulnerability-Patch Now!

A high-severity zero-day flaw tracked as CVE-2022-0609 in Google Chrome is exploited in attacks. It is finally resolving with the release of Chrome 98.0.4758.102 emergency update for Windows, Mac, and Linux. This is the first zero-day vulnerability Google has patched for Chrome this year, but it pro...

Feb 15, 2022By Gourav Shrivastava3 min read

A high-severity zero-day flaw tracked as CVE-2022-0609 in Google Chrome is exploited in attacks. It is finally resolving with the release of Chrome 98.0.4758.102 emergency update for Windows, Mac, and Linux. This is the first zero-day vulnerability Google has patched for Chrome this year, but it probably won’t be the last. However, this process will become easy by using a Patch Management Software.

“Google is aware of reports that an exploit for CVE-2022-0609 is being exploited in the wild,” referring to what it describes as a “use after free in Animation” flaw. Moreover, this was reported by Adam Weidemann and Clément Lecigne of Google’s own Threat Analysis Group. Reporting these vulnerabilities is easier with a Vulnerability Management Tool.

Endpoints that have not been patched are finally advised to deploy patches ASAP.

Zero-day Details Not Disclosed

Attackers commonly exploit use after free bugs to execute arbitrary code on computers running unpatched Chrome versions or escape the browser’s security sandbox. Google has not shared any additional info regarding these incidents nor released any technical details about the zero-day vulnerability.

“Access to bug details and links may be kept restricted until a majority of users are updated with a fix”, Google added.

Affected Products: Google Chrome Version: Prior 98.0.4758.102

CVE: CVE-2022-0603Description: The vulnerability exists due to a use-after-free error within the File Manager component in Google ChromeImpact: Successful exploitation may allow an attacker to compromise a vulnerable system.Severity: High

CVE: CVE-2022-0604Description: The vulnerability exists due to a boundary error when processing untrusted HTML content in Tab Groups.Impact: Successful exploitation of this vulnerability may result in the complete compromise of a vulnerable system.Severity: High

CVE: CVE-2022-0605Description:  The vulnerability exists due to a use-after-free error within the Webstore API component in Google Chrome.Impact: Successful exploitation may allow an attacker to compromise a vulnerable system.Severity: High

CVE:CVE-2022-0606Description: The vulnerability exists due to a use-after-free error within the ANGLE component in Google ChromeImpact: Successful exploitation may allow an attacker to compromise a vulnerable system.Severity: High

CVE: CVE-2022-0607Description: The vulnerability exists due to a use-after-free error within the GPU component in Google Chrome.Impact: Successful exploitation may allow an attacker to compromise a vulnerable system.Severity: High

CVE: CVE-2022-0608Description: The vulnerability exists due to integer overflow in the Mojo component in Google ChromeImpact: Successful exploitation of this vulnerability may result in the complete compromise of a vulnerable system.Severity: High

CVE: CVE-2022-0609Description: The vulnerability exists due to a use-after-free error within the Animation component in Google ChromeImpact: Successful exploitation may allow an attacker to compromise a vulnerable system.Severity: High

CVE: CVE-2022-0610Description: The vulnerability exists due to the incorrect implementation of Gamepad API in Google ChromeImpact: Successful exploitation allows a remote attacker to gain access to sensitive informationSeverity: Medium

SanerNow VM and SanerNow PM detect and automatically fix these vulnerabilities by applying security updates. Therefore Use SanerNow and keep your systems updated and secure.

Featured Posts

Open StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores
StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores

CVE Research

StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores

StyleSmuggler, an unpatched Magento and Adobe Commerce flaw letting attackers execute code without authentication via log poisoning, installing a persistent Linux backdoor that has already compromised live stores with no vendor patch available.

Sep 7, 2026

Open CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Flaw Enables Server Takeover
CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Vulnerability

CVE Research

CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Flaw Enables Server Takeover

Sep 7, 2026

Open Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212
Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE Research

Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE-2026-20212 is a critical vulnerability in Cisco Nexus 9000 Series Switches that use Silicon One ASICs. It allows an unauthenticated remote attacker to execute code with root privileges by sending crafted input to TCP ports 43210 and 43211, which are reachable in the default Layer 3 VRF. Exploitation can also crash the S1HAL process and force a device reload. This article covers how the vulnerability works, the affected product identifiers, its potential impact, available workarounds, and how to identify fixed software using the Cisco Software Checker.

Sep 4, 2026

Open SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution
SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

CVE Research

SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

Sep 3, 2026