Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-4135
- https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.html
- https://crbug.com/1392715
- https://github.com/electron/electron/pull/36444
- https://github.com/electron/electron/pull/36447
- https://github.com/advisories/GHSA-995f-9x5r-2rcj