← Vulnerability feed

Vulnerability record · CVE-2022-4135 · published 25 November 2022

CVE-2022-4135: Google Chrome GPU heap buffer overflow enables sandbox escape

Google · Chrome

Chrome's GPU component contains a heap buffer overflow (CWE-787) fixed in version 107.0.5304.121. An attacker who already controls the renderer process can use a crafted HTML page to break out of the browser sandbox. Because the sandbox is the main containment boundary, a successful escape exposes the underlying operating system.

9.6 CVSS 3.1 Critical CISA KEV since 28 Nov 2022 EPSS 32% · top 1.8% CWE-787 · Out-of-bounds write
9.6CVSS 3.1 base score
32%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
7References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.6, active inclusion in CISA KEV, and a high EPSS percentile make this a top remediation priority despite the renderer-compromise precondition.

What it is

Chrome's GPU component contains a heap buffer overflow (CWE-787) fixed in version 107.0.5304.121. An attacker who already controls the renderer process can use a crafted HTML page to break out of the browser sandbox. Because the sandbox is the main containment boundary, a successful escape exposes the underlying operating system.

Impact

An attacker with renderer code execution gains the ability to escape the Chrome sandbox and run code at the browser's privilege level on the host. This turns a contained renderer compromise into a full host compromise.

Attack surface

Reached over the network via a crafted HTML page, requiring user interaction (UI:R) to load it. No authentication or privileges are needed, but the attacker must first have compromised the renderer process, so this is a second-stage exploit rather than a standalone remote entry point.

Exploitation

Listed in CISA KEV with a 2022-11-28 addition and 2022-12-19 remediation due date, and a reference is tagged Exploit. EPSS 30-day probability is 0.31864 (98.2nd percentile), indicating high likelihood of attempted exploitation.

What to do

  • Update Chrome to 107.0.5304.121 or later, and apply the corresponding Microsoft Edge/Chromium updates.
  • Track the CISA KEV due date of 2022-12-19 and confirm all endpoints are patched.
  • Enforce automatic browser updates and verify version compliance across managed fleets.
  • Restrict or isolate high-risk browsing and block untrusted HTML content where feasible.
  • Monitor for follow-on host activity after any suspected renderer compromise.

Detection

  • Alert on Chrome/Edge versions below 107.0.5304.121 in asset inventory.
  • Hunt for browser processes spawning unexpected child processes or making anomalous outbound connections.
  • Review crash reports referencing the GPU process or crbug.com/1392715 for signs of exploitation attempts.
  • Correlate endpoint telemetry for sandbox-escape behavior such as unusual memory writes or privilege changes by browser processes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-4135 to the Known Exploited Vulnerabilities catalog on 28 November 2022 as "Google Chromium GPU Heap Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 19 December 2022.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-4135 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-10585Google Chrome V8 type confusion enables heap corruptionChrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that can lead to heap corruption when processing a crafted HTML page. It affec…KEVEPSS 5.4%analysed9.8CVE-2015-0313Adobe Flash Player use-after-free allows remote code executionAdobe Flash Player contains a use-after-free (CWE-416) flaw reachable through unspecified vectors. It affects Flash Player before 13.0.0.269 and 14.x…KEVEPSS 95%analysed9.8CVE-2015-0311Adobe Flash Player unspecified flaw allows remote code executionCVE-2015-0311 is an unspecified vulnerability in Adobe Flash Player affecting versions through 13.0.0.262, 14.x, 15.x, and 16.x through 16.0.0.287 on…KEVEPSS 86%analysed9.8CVE-2014-0497Adobe Flash Player integer underflow allows remote code executionAdobe Flash Player contains an integer underflow (CWE-191) that allows remote attackers to execute arbitrary code via unspecified vectors. The flaw a…KEVEPSS 100%analysed9.6CVE-2024-7971Google Chrome V8 type confusion enables heap corruptionChrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that lets a crafted HTML page corrupt the heap. It affects Chrome before 128.0…KEVEPSS 21%analysed9.6CVE-2024-5274Google Chrome V8 type confusion allows sandbox code executionGoogle Chrome before 125.0.6422.112 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and lea…KEVEPSS 7.5%analysed9.6CVE-2024-4947Google Chrome V8 type confusion allows sandboxed remote code executionGoogle Chrome before 125.0.6422.60 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and let …KEVEPSS 15%analysed9.6CVE-2024-4671Google Chrome Visuals use-after-free enables sandbox escapeCVE-2024-4671 is a use-after-free flaw in the Visuals component of Google Chrome prior to 124.0.6367.201. An attacker who has already compromised the…KEVEPSS 8.3%analysed

Source: NIST National Vulnerability Database (record CVE-2022-4135), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.