Google Patches Fifth Chrome Zero-Day of 2022 as Hackers Actively Exploit the Flaw

A flaw in how Chrome handles a mobile-linking feature is being weaponised in real attacks. It's the fifth time this year Google has had to rush out an emergency fix for its browser.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 2 min read
Extreme close-up of a glowing green padlock icon cracking apart on a dark laptop screen, shards of digital light scattering across a desk surface, shallow depth
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Google patched 11 security flaws in Chrome on Wednesday, 17 August 2022, one of which was already being actively exploited by hackers.
  • The exploited flaw, tracked as CVE-2022-2856, sits in a Chrome feature called Intents, a system that opens mobile apps directly from a web link.
  • Researchers Ashley Shen and Christian Resell, both from Google's Threat Analysis Group (TAG), reported the bug on 19 July 2022.
  • This is the fifth Chrome zero-day, meaning a flaw that was being attacked before Google knew it existed, patched so far in 2022.
  • A separate critical bug, CVE-2022-2852, was fixed in the same update.

Chrome, used by roughly two-thirds of people who browse the web, picked up an emergency security patch this week. Criminals were already walking through the hole it closes.

The flaw is CVE-2022-2856. It lives inside a Chrome feature called Intents, the mechanism that lets a web link open a specific app on your Android phone directly without making you find the app yourself. Chrome wasn't checking that incoming instructions through this channel were safe before acting on them, so a malicious link could sneak harmful instructions past that check and let an attacker run arbitrary code on a victim's device. That's about as bad as it gets.

How worried should everyday Chrome users be?

If your browser has updated in the last few days, you're almost certainly already protected. Chrome updates silently in the background for most users. Confirm you're covered by opening Chrome, clicking the three-dot menu, selecting Help, then About Google Chrome.

Google is staying quiet about exactly how the attacks work. That silence is deliberate: Microsoft Edge is built on the same underlying Chromium codebase, and it needs time to ship its own patch before a detailed attack recipe goes public. Satnam Narang, senior staff research engineer at Tenable, told Threatpost the caution is justified. Attackers, he noted, are ready to move the moment technical details surface, and patches take real time to reach every vulnerable machine.

The same update fixed a critical-rated bug, CVE-2022-2852, in FedCM, short for Federated Credential Management, a system that handles sign-in flows on the web. That bug was reported by Google Project Zero researcher Sergei Glazunov on 8 August 2022.

We covered a similar emergency V8 patch in Chrome Ships Emergency V8 Fix for CVE-2026-11645 Already Under Attack on 9 June 2026, and the same lesson applied: organisations that don't enforce automatic updates leave windows open that attackers measure in hours.

Five zero-days in eight months is a pace that should make anyone running a browser fleet uncomfortable. Update Chrome now.

© 2026 Threat Vectr