CVE-2022-1364: Google Chromium V8 Type Confusion Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-04-15. EPSS: 13.7% chance of exploitation in the next 30 days.

Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Affected products

  • Google Chrome: before 100.0.4896.127 (fixed in 100.0.4896.127)

Published 2022-07-26. Last modified 2026-06-17.