Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Google Chrome is a web browser used to access the Internet. Successful exploitation of the most severe of these vulnerabilities could allow an attacker to execute arbitrary code in the context of the applications. Depending on the privileges associated with the applications, an attacker could view, change, or delete data. If these applications have been configured to have fewer user rights on the system, exploitation of the most severe of these vulnerabilities could have less impact than if they were configured with administrative rights.
SYSTEMS AFFECTED:
RISK:
Government:
Businesses:
Home users: Low
TECHNICALSUMMARY:
Multiple vulnerabilities have been discovered in Chrome, the most severe of which could allow for arbitrary code execution. Details of the vulnerabilities are as follows:
Tactic: Execution (TA0002):
Technique: User Execution (T1204):
Details of lower-severity vulnerabilities are as follows:
Successful exploitation of the most severe of these vulnerabilities could allow an attacker to execute arbitrary code in the context of the applications. Depending on the privileges associated with the applications, an attacker could view, change, or delete data. If these applications have been configured to have fewer user rights on the system, exploitation of the most severe of these vulnerabilities could have less impact than if they were configured with administrative rights.
RECOMMENDATIONS:
We recommend the following actions be taken:
1. Apply the stable channel update provided by Google to vulnerable systems immediately after appropriate testing. (M1051: Update Software)
2. Remind users not to visit un-trusted websites or follow links provided by unknown or un-trusted sources. Inform and educate users regarding the threats posed by hypertext links contained in emails or attachments especially from un-trusted sources. (M1017: User Training)
3. Apply the Principle of Least Privilege to all systems and services. Run all software as a non-privileged user (one without administrative privileges) to diminish the effects of a successful attack. (M1026: Privileged Account Management)
4. Use capabilities to prevent suspicious behavior patterns from occurring on endpoint systems. This could include suspicious process, file, API call, etc. behavior. (M1040 : Behavior Prevention on Endpoint)
Safeguard 13.7: Deploy a Host-Based Intrusion Prevention Solution: Deploy a host-based intrusion prevention solution on enterprise assets, where appropriate and/or supported. Example implementations include use of an Endpoint Detection and Response (EDR) client or host-based IPS agent.
REFERENCES:
Google:https://chromereleases.googleblog.com/
CVE:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1853
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1854
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1855
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1856
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1857
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1858
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1859
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1860
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1861
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1862
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1863
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1864
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1865
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1866
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1867
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1868
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1869
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1870
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1871
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1872
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1873
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1874
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1875
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1876