{"id":"GHSA-995f-9x5r-2rcj","summary":"Heap buffer overflow in GPU","details":"Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)","aliases":["CVE-2022-4135"],"modified":"2023-11-01T05:28:42.581793Z","published":"2022-11-25T03:30:19Z","database_specific":{"nvd_published_at":"2022-11-25T01:15:00Z","cwe_ids":["CWE-787"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-11-28T23:33:19Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-4135"},{"type":"WEB","url":"https://github.com/electron/electron/pull/36444"},{"type":"WEB","url":"https://github.com/electron/electron/pull/36447"},{"type":"WEB","url":"https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.html"},{"type":"WEB","url":"https://crbug.com/1392715"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202305-10"}],"affected":[{"package":{"name":"electron","ecosystem":"npm","purl":"pkg:npm/electron"},"ranges":[{"type":"SEMVER","events":[{"introduced":"19.0.0"},{"fixed":"19.1.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-995f-9x5r-2rcj/GHSA-995f-9x5r-2rcj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}