LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-4135: Google Chromium GPU Heap Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 28, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 19, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-4135 to its Known Exploited Vulnerabilities catalog on Nov 28, 2022, with a federal patch deadline of Dec 19, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML…

CVE-2022-4135 is a heap buffer overflow in the GPU component of Google Chromium. An attacker who has already compromised the browser's renderer process can use a crafted HTML page to attempt a sandbox escape. Because Chromium underpins multiple browsers, the issue can affect Google Chrome, Microsoft Edge, Opera and other Chromium-based products. Sandbox escapes matter because they can let malicious code move beyond the browser's isolation boundaries and interact with the host system.

Defenders should treat this as a high-priority browser vulnerability: confirm the exact status of every Chromium-based browser in the environment against the vendor advisory and apply the required updates without delay.

How it works

The weakness is classified as CWE-787 (out-of-bounds write). In a heap buffer overflow, code writes data past the end of an allocated memory buffer on the heap. When that write occurs inside Chromium's GPU process, an attacker who already controls the renderer can supply a specially crafted HTML page that triggers the overflow. Successful abuse may allow the attacker to break out of the browser sandbox and gain additional privileges or access on the host.

Public detail on the precise trigger or memory layout is limited; the CISA summary states only that a remote attacker who has compromised the renderer can potentially perform a sandbox escape via crafted HTML. No further exploit mechanics are provided here, so any technical investigation must rely on the vendor advisory and subsequent analysis rather than assumptions.

Am I affected? How to find it in your systems

The vulnerability resides in the GPU component of Google Chromium and therefore can affect any browser that embeds Chromium, including but not limited to Google Chrome, Microsoft Edge and Opera. These browsers commonly run on Windows, macOS and Linux endpoints used by employees, contractors and kiosks.

If the browser is present and has not yet received the vendor-supplied update, treat the system as potentially affected until confirmed otherwise.

How to remediate

The primary remediation is to apply the updates issued by the browser vendors, exactly as directed in their advisories. CISA's required action is simply to apply updates per vendor instructions.

Once the vendor update is in place, the heap buffer overflow is addressed at the source. Additional hardening for this class of flaw includes keeping the browser's sandbox features enabled, running browsers under least-privilege accounts, and restricting the ability of untrusted content to exercise GPU-accelerated features when policy allows.

If you can't patch immediately

When immediate patching is not possible, reduce exposure with compensating controls while the update is prepared.

These measures lower the likelihood of successful sandbox escape but do not eliminate the underlying flaw; schedule the official update as soon as operational constraints allow.

If your data may have been exposed

Actively exploited browser vulnerabilities can lead to full system compromise and subsequent data theft. Although ransomware use of this specific CVE is not documented, any confirmed sandbox escape should be treated as a potential breach. Review endpoint and network logs for signs of post-exploitation activity, isolate affected hosts, and follow your incident-response plan. As a quick check for personal or organizational email addresses that may already appear in known breach data sets, run a free exposure scan of the relevant addresses.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGoogle · Chromium GPU
WeaknessCWE-787
Added to CISA KEVNov 28, 2022
Federal patch deadlineDec 19, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities