Vulnerability record · CVE-2022-0306 · published 12 February 2022
CVE-2022-0306: Google Chrome PDFium heap buffer overflow via crafted HTML page
Google · Chrome
PDFium in Google Chrome before 97.0.4692.99 contains a heap buffer overflow (out-of-bounds write) that can corrupt heap memory. A remote attacker can trigger it with a crafted HTML page, and the flaw was fixed in the January 2022 stable channel update.
Description
Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityHigh CVSS (8.8) and very high EPSS probability, but no KEV listing or documented in-the-wild exploitation.
What it is
PDFium in Google Chrome before 97.0.4692.99 contains a heap buffer overflow (out-of-bounds write) that can corrupt heap memory. A remote attacker can trigger it with a crafted HTML page, and the flaw was fixed in the January 2022 stable channel update.
Impact
Successful exploitation can corrupt heap memory and potentially lead to code execution in the browser process context. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network by rendering a crafted HTML page in Chrome; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N).
Exploitation
Not listed in CISA KEV and no ransomware usage is documented; EPSS is very high (0.85352, 99.7th percentile), and references include a Packet Storm advisory and the vendor release notes.
What to do
- Update Google Chrome to 97.0.4692.99 or later, and restart the browser so the update takes effect.
- Track Chrome version compliance across managed endpoints and enforce automatic updates where possible.
- Restrict or disable the built-in PDF viewer in high-risk environments if it is not required.
- Apply browser isolation or sandboxing controls for untrusted web content.
Detection
- Monitor for Chrome crashes or renderer process terminations that could indicate heap corruption attempts.
- Hunt for known PDFium heap overflow proof-of-concept or exploit artifacts in web proxy and endpoint logs.
- Check endpoint inventories for Chrome versions below 97.0.4692.99.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/166367/Chrome-chrome_pdf-PDFiumEngine-RequestThumbnail-Heap-Buffer-Overflow.html | Third Party AdvisoryVDB Entry |
| https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop_19.html | Release NotesVendor Advisory |
| https://crbug.com/1283198 | Issue TrackingPermissions RequiredThird Party Advisory |
| http://packetstormsecurity.com/files/166367/Chrome-chrome_pdf-PDFiumEngine-RequestThumbnail-Heap-Buffer-Overflow.html | Third Party AdvisoryVDB Entry |
| https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop_19.html | Release NotesVendor Advisory |
| https://crbug.com/1283198 | Issue TrackingPermissions RequiredThird Party Advisory |
Track CVE-2022-0306 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-0306), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.