Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HSummary
CVE-2022-1096 is a high-severity Type Confusion (CWE-843) vulnerability in Google Chrome. Its CVSS base score is 8.8 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked in the top 2% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2022-1096 is a type confusion vulnerability in the V8 JavaScript engine within Google Chrome versions prior to 99.0.4844.84. The flaw, tracked under CWE-843, can result in heap corruption when processing specially crafted input.
A remote attacker can exploit the issue by convincing a target to visit a malicious HTML page, achieving high impact on confidentiality, integrity, and availability without requiring authentication or user privileges beyond normal browser interaction.
Chrome stable channel updates released on March 25, 2022, address the vulnerability by advancing the browser to version 99.0.4844.84 or later, and downstream distributions such as Gentoo have issued corresponding advisories recommending prompt upgrades.
The associated EPSS score rose from lower values after disclosure to a peak of 0.5254 on 2025-12-18 before receding to the current 0.3766, indicating renewed exploitation interest well after the initial publication.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2022-24439
Vulnerability Data
Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CWE(s)
- KEV Date Added
- 28 March 2022
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V1.5.2V3.2.3V15.3.5
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly prevent type-confusion flaws via safe typing, static analysis, and code review while the control itself addresses many additional weaknesses.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing in development can detect type-confusion vulnerabilities through fuzzing and static analysis.
Secure SDLC mandates type-safe design and review that can catch type-confusion flaws.
Application security requirements can specify strong typing and interface contracts that reduce type confusion.
Secure architecture principles promote type-safe languages and memory-safety mechanisms that mitigate type confusion.
Secure coding standards directly forbid unsafe type casts and require static-analysis checks for type confusion.