CVE-2022-4135
published 2022-11-25CVE-2022-4135: Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform…
PriorityP188critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-12-19
Exploited in the wild
EPSS
31.86%
98.1th percentile
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 107.0.5304.121-1~deb11u1 | 107.0.5304.121-1~deb11u1 |
| chromium | chromium | >= 0 < 107.0.5304.121-1 | 107.0.5304.121-1 |
| chromium | chromium | >= 0 < 107.0.5304.121-1 | 107.0.5304.121-1 |
| chromium | chromium | >= 0 < 107.0.5304.121-1 | 107.0.5304.121-1 |
| debian | chromium | < chromium 107.0.5304.121-1 (bookworm) | chromium 107.0.5304.121-1 (bookworm) |
| electron | electron | >= 19.0.0 < 19.1.8 | 19.1.8 |
| chrome | < 107.0.5304.121 | 107.0.5304.121 | |
| chrome | >= unspecified < 107.0.5304.121 | 107.0.5304.121 | |
| chrome_chrome | — | — | |
| microsoft | edge | < 107.0.1418.62 | 107.0.1418.62 |
| microsoft | edge_chromium | < 107.0.5304.150 | 107.0.5304.150 |
| msrc | microsoft_edge | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2022-4135 is a heap buffer overflow in the GPU component of Google Chrome; exploitation requires the attacker to have already compromised the renderer process, enabling a sandbox escape via a crafted HTML page. ↗
- →Google has confirmed an in-the-wild exploit exists for CVE-2022-4135; treat any Chrome process crashing in the GPU component as a high-priority triage signal. ↗
- →The vulnerability affects multiple Chromium-based browsers (Chrome, Microsoft Edge, Opera); detection/patching scope should cover all Chromium-based browser deployments, not just Chrome. ↗
- →CISA mandated remediation by 2022-12-19; any unpatched Chromium-based browser (Chrome < 107.0.5304.121) in the environment after that date should be flagged as a critical finding. ↗
- ·Google withheld technical vulnerability details at time of disclosure to limit exploitation spread; no public PoC or technical write-up was available in these sources, limiting signature-based detection options. ↗
- ·Microsoft Edge (Chromium-based) is also affected and requires its own patch (Stable 107.0.1418.62 / Chromium 107.0.5304.150, released 2022-11-28); patching Chrome alone is insufficient in mixed-browser environments. ↗
CVSS provenance
nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
osv9.6CRITICAL
vulncheck9.6CRITICAL
cisa9.6CRITICAL
vendor_debian9.6CRITICAL
vendor_msrc9.6CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2022-4135
vendor_chrome·2022-12-14·CVSS 9.6
CVE-2022-4135 [CRITICAL] Long Term Support Channel Update for ChromeOS: CVE-2022-4135
Long Term Support Channel Update for ChromeOS
CVE-2022-4135
CISA
Google Chromium GPU Heap Buffer Overflow Vulnerability
cisa·2022-11-28·CVSS 9.6
CVE-2022-4135 [CRITICAL] CWE-787 Google Chromium GPU Heap Buffer Overflow Vulnerability
Vulnerability: Google Chromium GPU Heap Buffer Overflow Vulnerability
Affected: Google Chromium GPU
Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Required Action: Apply updates per vendor instructions.
Notes: https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.html; https://nvd.nist.gov/vuln/detail/CVE-2022-4135
Remediation Due Date: 2022-12-19
Microsoft
Chromium: CVE-2022-4135 Heap buffer overflow in GPU
vendor_msrc·2022-11-08·CVSS 9.6
CVE-2022-4135 [CRITICAL] Chromium: CVE-2022-4135 Heap buffer overflow in GPU
Chromium: CVE-2022-4135 Heap buffer overflow in GPU
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Google is aware that an exploit for CVE-2022-4135 exists in the wild.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the wi
Debian
CVE-2022-4135: chromium - Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a r...
vendor_debian·2022·CVSS 9.6
CVE-2022-4135 [CRITICAL] CVE-2022-4135: chromium - Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a r...
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 107.0.5304.121-1)
bullseye: resolved (fixed in 107.0.5304.121-1~deb11u1)
forky: resolved (fixed in 107.0.5304.121-1)
sid: resolved (fixed in 107.0.5304.121-1)
trixie: resolved (fixed in 107.0.5304.121-1)
GHSA
Heap buffer overflow in GPU
ghsa·2022-11-25
CVE-2022-4135 [CRITICAL] CWE-787 Heap buffer overflow in GPU
Heap buffer overflow in GPU
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
OSV
Heap buffer overflow in GPU
osv·2022-11-25
CVE-2022-4135 [CRITICAL] Heap buffer overflow in GPU
Heap buffer overflow in GPU
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
OSV
CVE-2022-4135: Heap buffer overflow in GPU in Google Chrome prior to 107
osv·2022-11-25·CVSS 9.6
CVE-2022-4135 [CRITICAL] CVE-2022-4135: Heap buffer overflow in GPU in Google Chrome prior to 107
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
VulnCheck
Google Chromium GPU Heap Buffer Overflow Vulnerability
vulncheck·2022·CVSS 9.6
CVE-2022-4135 [CRITICAL] CWE-787 Google Chromium GPU Heap Buffer Overflow Vulnerability
Google Chromium GPU Heap Buffer Overflow Vulnerability
Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Affected: Google Chromium GPU
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://raw.githubusercontent.com/blackorbird/APT_REPORT/master/summary/2023/360_APT_Annual_Research_
Project0
Project Zero RCA: CVE-2022-4135: Chrome heap buffer overflow in validating command decoder
project_zero·CVSS 9.6
CVE-2022-4135 [CRITICAL] Project Zero RCA: CVE-2022-4135: Chrome heap buffer overflow in validating command decoder
# CVE-2022-4135: Chrome heap buffer overflow in validating command decoder
*Sergei Glazunov, Google Project Zero*
## The Basics
**Disclosure or Patch Date:** 24 November 2022
**Product:** Google Chrome
**Advisory:** https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.html
**Affected Versions:** pre 107.0.5304.121
**First Patched Version:** 107.0.5304.121
**Issue/Bug Report:** https://bugs.chromium.org/p/chromium/issues/detail?id=1392715
**Patch CL:** https://chromium.googlesource.com/chromium/src/+/2bd6ab1a16090fd20d422c11d794edf5c0ff6b89
**Bug-Introducing CL:** N/A
**Reporter(s):** Clement Lecigne of Google's Threat Analysis Group
## The Code
**Proof-of-concept:**
*repro.diff*
```
diff --git a/third_party/blink/renderer/modules/webgl/webgl_rende
No detection rules found.
No public exploits indexed.
Qualys
The 9th Google Chrome Zero-Day Threat this Year – Again Just Before the Weekend
blogs_qualys·2022-12-03·CVSS 8.8
CVE-2022-4262 [HIGH] The 9th Google Chrome Zero-Day Threat this Year – Again Just Before the Weekend
## Table of Contents
Organizations respond, but slowly
Qualys Patch Management speeds remediation
Google has released yet another security update for the Chrome desktop web browser to address a high-severity vulnerability that is being exploited in the wild. This is the ninth Chrome zero-day fixed this year by Google. This security bug ( CVE-2022-4262 ; QID 377804 ) is a Type Confusion vulnerability in Chrome’s V8 JavaScript Engine.
Google has withheld details about the vulnerability to prevent expanding its malicious exploitation and to allow users time to apply the security updates necessary on their Chrome installations.
Google’s previous zero-days were also released right before a weekend (see Don’t spend another weekend patching Chrome and Don’t Spend Your Holiday Season Patching
Qualys
Don’t Spend Your Holiday Season Patching Chrome
blogs_qualys·2022-11-29·CVSS 9.6
CVE-2022-4135 [CRITICAL] Don’t Spend Your Holiday Season Patching Chrome
## Table of Contents
Zero-touch patching of 3rd-party applications
How Qualys Patch Management can help drive speed of remediation
As we come back from our Thanksgiving holidays, Google has released yet another security update for the Chrome desktop web browser to address a high-severity vulnerability that exists in the wild. This is the eighth Chrome zero-day fixed this year by Google. This security bug ( CVE-2022-4135 ; QID 377794 ) is a Heap buffer overflow in GPU.
Google has withheld details about the vulnerability to prevent expanding its malicious exploitation and to allow users time to apply the security updates necessary on their Chrome installations.
Google’s previous zero-day was also released right before a weekend (see Don’t spend another weekend patching Chrome ).
## Zer
Qualys
Don’t Spend Your Holiday Season Patching Chrome | Qualys
blogs_qualys·2022-11-29·CVSS 9.6
CVE-2022-4135 [CRITICAL] Don’t Spend Your Holiday Season Patching Chrome | Qualys
#### Table of Contents
- Zero-touch patching of 3rd-party applications
- How Qualys Patch Management can help drive speed of remediation
As we come back from our Thanksgiving holidays, Google has released yet another security update for the Chrome desktop web browser to address a high-severity vulnerability that exists in the wild. This is the eighth Chrome zero-day fixed this year by Google. This security bug (CVE-2022-4135; QID 377794) is a Heap buffer overflow in GPU.
Google has withheld details about the vulnerability to prevent expanding its malicious exploitation and to allow users time to apply the security updates necessary on their Chrome installations.
Google’s previous zero-day was also released right before a weekend (see Don’t spend another weekend patching Chrome).
## Ze
Checkpoint
28th November– Threat Intelligence Report
blogs_checkpoint·2022-11-28
CVE-2022-4135 28th November– Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 28th November– Threat Intelligence Report
For the latest discoveries in cyber research for the week of 28th November, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The European Parliament website has been attacked following a vote declaring Russia a state sponsor of terrorism. The pro-Russian hacktivist groups Anonymous Russia and Killnet, have claimed responsibility for the attack, causing an ongoing DDoS (Distributed Denial of Service).
Ukrainian organizations have been a victim
https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.htmlhttps://crbug.com/1392715https://security.gentoo.org/glsa/202305-10https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.htmlhttps://crbug.com/1392715https://security.gentoo.org/glsa/202305-10https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-4135
2022-11-25
Published
2022-11-28
Added to CISA KEV
Exploited in the wild