ZeroHour

CVE-2022-4135

KEV PoC mass

Chromium GPU heap buffer overflow enables sandbox escape (affects Chrome, Edge, Opera)

CISA: Google Chromium GPU Heap Buffer Overflow Vulnerability

CVSS 3.1
9.6 critical
EPSS
32%p98
Published
()
KEV added
AI analysis

CVE-2022-4135 is a heap buffer overflow (CWE-787, out-of-bounds write) in the GPU process of Google Chromium, the browser engine behind Chrome and most other major browsers. It is triggered via a crafted HTML page and, per CISA, requires the attacker to have already compromised the browser's renderer process; the memory corruption in the GPU process can then be leveraged to escape the renderer sandbox. A successful attack moves the attacker out of the tightly restricted renderer sandbox toward the higher-privilege GPU process on the host, a step that can enable further code execution. All users of Chromium-based browsers are affected — CISA explicitly lists Google Chrome, Microsoft Edge, and Opera, among others — though no specific vulnerable version ranges are published in the source data. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-11-28, EPSS assigns a 31.9% probability of exploitation within 30 days (98th percentile), and no public proof-of-concept is known.

What to do: Treat unpatched Chromium-based browsers as exposed and apply vendor updates immediately, per CISA's required action: update Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers to the latest patched releases available as of the late-November 2022 KEV listing. Inventory managed endpoints for browser versions and verify auto-update is enabled, since the flaw is confirmed exploited in the wild even though no public PoC exists.

Affected
Google Chromium GPU (GPU process component of the Chromium engine)
Google Chrome (Chromium-based browser)
Microsoft Edge (Chromium-based browser)
Opera (Chromium-based browser)
Estimated exposure
mass≈billions of users across Google Chrome, Microsoft Edge, Opera and other Chromium-based browsers (exact count unknown) — Chromium is the engine for Chrome, which accounts for a majority of global desktop browser usage, plus Edge, Opera, and many other Chromium-derived and embedded browsers, making the plausibly exposed population on the order of billions of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CISA Known Exploited Vulnerability
Affected
Google Chromium GPU
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlemicrosoft
Products
chrome, edge, edge chromium
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news