CVE-2022-4135 is a critical heap buffer overflow vulnerability in the GPU component of Google Chrome and related Chromium-based browsers, including Microsoft Edge. This flaw, rated 9.6 CRITICAL, allows a remote attacker to potentially escape the browser's sandbox via a crafted HTML page after compromising the renderer process. Google has confirmed active exploitation of this zero-day vulnerability in the wild, leading to emergency updates. Despite no public exploit code, the high number of community discussions and media coverage underscore its significant threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 107.0.5304.121CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 107.0.1418.62CPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* | ||
< 107.0.5304.150CPE matchmatch criteria | cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.