CVE-2022-4135

CRITICAL9.6⚠ KEVEPSS 0.08%

Heap buffer overflow in GPU

Published: 11/25/2022Modified: 11/8/2023Added to CISA KEV: 11/28/2022
Also known as:GHSA-995f-9x5r-2rcj

Description

Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

References (7)