

Google says this zero-day vulnerability was exploited in the wild and does not yet share technical details or any info regarding these incidents. The attacker behind this exploit is still unknown. The Zero-day bug affected both Windows and Android versions and the bug was reported by Jan Vojtesek from the Avast Threat Intelligence team. High CVE-2022-2296: Use after free in Chrome OS Shell.High CVE-2022-2294: Heap buffer overflow in WebRTC.Here are the other bugs that were fixed in this new security update:

“A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc()”.
