Vulnerability record · CVE-2022-4135 · published 25 November 2022
CVE-2022-4135: Google Chrome GPU heap buffer overflow enables sandbox escape
Google · Chrome
Chrome's GPU component contains a heap buffer overflow (CWE-787) fixed in version 107.0.5304.121. An attacker who already controls the renderer process can use a crafted HTML page to break out of the browser sandbox. Because the sandbox is the main containment boundary, a successful escape exposes the underlying operating system.
Description
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.6, active inclusion in CISA KEV, and a high EPSS percentile make this a top remediation priority despite the renderer-compromise precondition.
What it is
Chrome's GPU component contains a heap buffer overflow (CWE-787) fixed in version 107.0.5304.121. An attacker who already controls the renderer process can use a crafted HTML page to break out of the browser sandbox. Because the sandbox is the main containment boundary, a successful escape exposes the underlying operating system.
Impact
An attacker with renderer code execution gains the ability to escape the Chrome sandbox and run code at the browser's privilege level on the host. This turns a contained renderer compromise into a full host compromise.
Attack surface
Reached over the network via a crafted HTML page, requiring user interaction (UI:R) to load it. No authentication or privileges are needed, but the attacker must first have compromised the renderer process, so this is a second-stage exploit rather than a standalone remote entry point.
Exploitation
Listed in CISA KEV with a 2022-11-28 addition and 2022-12-19 remediation due date, and a reference is tagged Exploit. EPSS 30-day probability is 0.31864 (98.2nd percentile), indicating high likelihood of attempted exploitation.
What to do
- Update Chrome to 107.0.5304.121 or later, and apply the corresponding Microsoft Edge/Chromium updates.
- Track the CISA KEV due date of 2022-12-19 and confirm all endpoints are patched.
- Enforce automatic browser updates and verify version compliance across managed fleets.
- Restrict or isolate high-risk browsing and block untrusted HTML content where feasible.
- Monitor for follow-on host activity after any suspected renderer compromise.
Detection
- Alert on Chrome/Edge versions below 107.0.5304.121 in asset inventory.
- Hunt for browser processes spawning unexpected child processes or making anomalous outbound connections.
- Review crash reports referencing the GPU process or crbug.com/1392715 for signs of exploitation attempts.
- Correlate endpoint telemetry for sandbox-escape behavior such as unusual memory writes or privilege changes by browser processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-4135 to the Known Exploited Vulnerabilities catalog on 28 November 2022 as "Google Chromium GPU Heap Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 19 December 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.html | Release NotesVendor Advisory |
| https://crbug.com/1392715 | ExploitIssue Tracking |
| https://security.gentoo.org/glsa/202305-10 | Third Party Advisory |
| https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.html | Release NotesVendor Advisory |
| https://crbug.com/1392715 | ExploitIssue Tracking |
| https://security.gentoo.org/glsa/202305-10 | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-4135 | US Government Resource |
Track CVE-2022-4135 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-4135), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.