CVE-2022-1096
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
14 articles
EPSS Score
Source: FIRST.org · 2026-05-24
37.66%
probability
This CVE has a 37.66% probability
of being exploited in the next 30 days.
0%
Top 97.3th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroType confusion in V8
Attack Intelligence
Google Project Zero
Discovered
March 23, 2022
Patched
March 25, 2022
Reported by
???
Root Cause Analysis
https://googleprojectzero.github.io/0days-in-the-wild//0day-RCAs/2022/CVE-2022-1096.html
Exploits & PoC
Mav3r1ck0x1/Chrome-and-Edge-Version-Dumper
Powershell script that dumps Chrome and Edge version to a text file in order to determine if you need to update due to CVE-2022-1096
3
1 repo — triés par ⭐
Rechercher sur GitHub ↗
Emergency Google Chrome update fixes zero-day used in attacks
BleepingComputer
Mar 25, 2022
Google Chrome emergency update fixes new zero-day used in attacks
BleepingComputer
Sep 02, 2022
Google Rolls Out New Chrome Browser Update to Patch Yet Another Zero-Day Vulnerability
TheHackerNews
Google Chrome emergency update fixes 9th zero-day of the year
BleepingComputer
Dec 02, 2022
Google fixes fifth Chrome zero-day bug exploited this year
BleepingComputer
Aug 17, 2022
Google Chrome emergency update fixes zero-day used in attacks
BleepingComputer
Apr 14, 2022
Google pushes emergency Chrome update to fix 8th zero-day in 2022
BleepingComputer
Nov 25, 2022
Google patches new Chrome zero-day flaw exploited in attacks
BleepingComputer
Jul 04, 2022
Google fixes seventh Chrome zero-day exploited in attacks this year
BleepingComputer
Oct 28, 2022
Security Advisory 2023-024
CERT-EU
Apr 18, 2023
Signal Intelligence
Confidence
85%
EPSS
37.66%
Mentions
14
Last Seen
Apr 18, 2023
CNA Information
Analyst Note
CVE-2022-1096 is a high-severity type confusion vulnerability in Chrome V8 with confirmed Google Project Zero involvement and official vendor patching in version 99.0.4844.84, providing strong evidence of legitimacy. The CVSS 8.8 rating reflects significant heap corruption exploitation potential. While limited public article coverage exists, the combination of Google's acknowledgment, Project Zero research, and official patching strongly validates the confirmed classification.
Threat Actors 3
Cobalt
apt_group
Financial crime
🇷🇺 RU
Luna Moth
apt_group
Operation Cobalt Whisper
apt_group
Financial crime
🇨🇳 CN
Triage Info
Decided atMar 03, 2026