NVD disclosure day

Published threat advisories for September 26, 2022

CVE advisoryKnown Exploit

CVE-2022-3075

Google Chrome Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Chrome's Mojo component could allow a remote attacker to escape the browser's sandbox, impacting data and system confidentiality and integrity. Organizations using affected Chrome versions face business risk if users interact with malicious web pages.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2022-2856

Google Chrome Android: Malicious Website Browsing Risk

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Chrome on Android could allow attackers to redirect users to malicious websites. This impacts organizations by potentially exposing employees to phishing or malware. Affected systems include instances of Chrome on Android. The business risk involves credential theft or further malware infectio

• CISA KEV

CVE advisoryKnown Exploit

CVE-2022-41352

Zimbra Collaboration Suite Arbitrary File Upload Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A file upload vulnerability in Zimbra Collaboration Suite allows attackers to execute arbitrary code, potentially compromising user accounts and sensitive data. This issue presents a significant business risk due to its exploitability over a network by unauthenticated attackers. Organizations should apply vendor patche

• CISA KEV