CRITICAL
CVE-2022-4135
CVSS
9.6
KEV
Description
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Summary dbcve.org
Heap buffer overflow vulnerability in Google Chrome's GPU process prior to version 107.0.5304.121. A remote attacker with a compromised renderer process could exploit this via a crafted HTML page to potentially escape the sandbox and execute code in the GPU process context.
Mitigation
Update Google Chrome to version 107.0.5304.121 or later to remediate this vulnerability. Organizations should deploy the update across all endpoints via patch management.
Weakness (CWE)
CWE-787
Out-of-bounds Write
EPSS Score
31.86%
Probability of exploitation in next 30 days
98.2th percentile
References
https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.html
Release Notes, Vendor Advisory
https://crbug.com/1392715
Exploit, Issue Tracking
https://security.gentoo.org/glsa/202305-10
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-4135
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.