CVE-2022-4135
Google Chromium GPU Heap Buffer Overflow Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 19 December 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVSS 3.1
- 9.6 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- EPSS
- 31.86% probability · 98th percentile
- CISA KEV
- Listed 28 November 2022 · due 19 December 2022
- Weakness
- CWE-787
- Affected
- google/chrome · microsoft/edge · microsoft/edge chromium
- Source
- chrome-cve-admin@google.com
CISA notes
Apply updates per vendor instructions. https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.html; https://nvd.nist.gov/vuln/detail/CVE-2022-4135
References
- https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.htmlRelease Notes, Vendor Advisory
- https://crbug.com/1392715Exploit, Issue Tracking
- https://security.gentoo.org/glsa/202305-10Third Party Advisory
- https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.htmlRelease Notes, Vendor Advisory
- https://crbug.com/1392715Exploit, Issue Tracking
- https://security.gentoo.org/glsa/202305-10Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-4135US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.