CRITICAL

CVE-2022-4135

Google Chrome 2022-11-25 CVSS v3.1
CVSS
9.6
KEV

Description

Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Summary dbcve.org

Heap buffer overflow vulnerability in Google Chrome's GPU process prior to version 107.0.5304.121. A remote attacker with a compromised renderer process could exploit this via a crafted HTML page to potentially escape the sandbox and execute code in the GPU process context.

Mitigation

Update Google Chrome to version 107.0.5304.121 or later to remediate this vulnerability. Organizations should deploy the update across all endpoints via patch management.

Proof of Concept

Weakness (CWE)

CWE-787 Out-of-bounds Write

EPSS Score

31.86%
Probability of exploitation in next 30 days
98.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE