Threat Advisory

Google releases chrome patch to fix new zero-day vulnerability

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

Google have released a patch for a newly found zeroday vulnerability tracked as CVE-2022-4135. CVE-2022-4135 is a Heap buffer overflow in GPU in Google Chrome which allows a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. If exploited successfully it could allow the attacker to overwrite the application's memory to manipulate its execution path, resulting in unrestricted information access or arbitrary code execution.[/subscribe_to_unlock_form]

Summary:

Google have released a patch for a newly found zeroday vulnerability tracked as CVE-2022-4135. CVE-2022-4135 is a Heap buffer overflow in GPU in Google Chrome which allows a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. If exploited successfully it could allow the attacker to overwrite the application's memory to manipulate its execution path, resulting in unrestricted information access or arbitrary code execution.[emaillocker id="1283"]

Recommendation:

We strongly recommend patching the vulnerability by updating to the latest version

  • Update to latest version 107.0.5304.121 for macOS and Linux  
  • Update to latest version 107.0.5304.121/.122 for Windows

References:

The following reports contain further technical details:

https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop.html

[/emaillocker]
crossmenu