The US Cybersecurity and Infrastructure Security Agency (CISA) has added a Type Confusion bug in Google Chromium V8to its list of Known Exploited Vulnerabilities ( KEV).

The vulnerability is tracked as CVE-2023-4762 and affects Google Chrome before version 116.0.5845.179. It could allow a remote attacker to execute code via a crafted HTML page.
See also: New vulnerabilities in Cisco, Fortinet, VMware require immediate updates
In September 2023, Citizen Lab and Google security researchers revealed that three recently patched zero-day vulnerabilities in Apple products (CVE-2023-41993, CVE-2023-41991, CVE-2023-41992) were used to install spyware. One of the exploit chains for the above bugs was through the CVE-2023-4762 exploit
“The attacker also had an exploit chain to install Predator on Android devices in Egypt. Researchers observed these exploits being delivered in two different ways: via MITM injection and via one-time links sent directly to the target. We were only able to obtain the renderer remote code execution vulnerability for Chrome, which exploited CVE-2023-4762,” the researchers. “We estimate that Intellexa has previously used this vulnerability as a 0-day.”
According to CISA, U.S. federal agencies must address the vulnerabilities listed by a certain date. Alternatively, they must stop using the vulnerable systems. In this case, CISA is ordering federal agencies to fix this vulnerability by February 27, 2024.
See also: New vulnerabilities in Azure HDInsight Spark, Kafka, and Hadoop services

Experts also recommend that private organizations review the Catalog and also fix the vulnerabilities themselves.
CISA's KEV list is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization.
Overall, CISA helps a lot in protecting and addressing cybersecurity threats. This organization works with various sectors, such as private businesses, state governments, and local authorities, to improve the security of digital systems.
See also: Linux: Critical vulnerability affects most distributions by introducing bootkits
It provides information and tools to help organizations protect their networks from cyberattacks and respond to any attacks that may occur. It also informs the public about any vulnerabilities in widely used systems and applications.
Overall, CISA's role is vital to protecting the digital infrastructure of the US and other regions.
Source: securityaffairs.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
