CVE-2022-1364

HIGH KEV

Google Chrome < 100.0.4896.127 - Type Confusion in V8 Turbofan

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-1364 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added April 15, 2022. EIP tracks 2 public exploits from researchers including interruptlabs, A1Lin.

AI-analyzed exploit summary This is a working PoC for CVE-2022-1364, a remote code execution vulnerability in UC Browser. The exploit leverages a type confusion bug in the V8 JavaScript engine to achieve arbitrary read/write primitives, followed by WebAssembly-based shellcode execution.

Description

Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Exploits (2)

nomisec WORKING POC 10 stars
by interruptlabs · client-side
https://github.com/interruptlabs/uc_browser_poc_CVE-2022-1364

This is a working PoC for CVE-2022-1364, a remote code execution vulnerability in UC Browser. The exploit leverages a type confusion bug in the V8 JavaScript engine to achieve arbitrary read/write primitives, followed by WebAssembly-based shellcode execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: UC Browser (versions prior to late 2024 patch)
No auth needed
Prerequisites: Victim must visit a malicious webpage · UC Browser version vulnerable to CVE-2022-1364
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 2 stars
by A1Lin · client-side
https://github.com/A1Lin/cve-2022-1364

The repository contains only a README file stating the exploit was tested against Bromite v95.0.4638.79. No actual exploit code or technical details are provided.

Classification
Writeup 30%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Bromite v95.0.4638.79
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Issue Tracking, Patch, Vendor Advisory x_refsource_misc
https://crbug.com/1315901
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202208-25

Scores

CVSS v3 8.8
EPSS 0.1372
EPSS Percentile 96.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-04-15
VulnCheck KEV 2022-04-13
InTheWild.io 2022-04-13
ENISA EUVD EUVD-2022-24685
CWE
CWE-843
Status published
Products (1)
google/chrome < 100.0.4896.127
Published Jul 26, 2022
KEV Added Apr 15, 2022
Tracked Since Feb 18, 2026