CVE-2022-4920: Heap buffer overflow in Blink
Published Mar 16, 2022
·Updated
Heap buffer overflow in Blink in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Credit
Shih-Fong Peng@@_L4ys(TrapaSecurity)
Affected Software
2 affected componentsFixes available
Google Chrome<101.0.4951.41
101.0.4951.41
Google Chrome<101.0.4951.41
Event History
Mar 16, 2022
CVE Published
12:00 AM
Jul 28, 2023
CVE Published
via MITRE·11:26 PM
Data Sourced
via MITRE·11:26 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-1477
- CVE-2022-1478
- CVE-2022-1479
- CVE-2022-1481
- CVE-2022-1919
- CVE-2022-4919
- CVE-2022-1482
- CVE-2022-1483
- CVE-2022-1484
- CVE-2022-1485
- CVE-2022-1486
- CVE-2022-1487
- CVE-2022-1488
- CVE-2022-1489
- CVE-2022-1490
- CVE-2022-1491
- CVE-2022-1492
- CVE-2022-1493
- CVE-2022-1494
- CVE-2022-1495
- CVE-2022-1496
- CVE-2022-1497
- CVE-2022-1498
- CVE-2022-1499
- CVE-2022-1500
- CVE-2022-1501
Frequently Asked Questions
1
What is the severity of CVE-2022-4920?
The severity of CVE-2022-4920 is classified as High.
2
How do I fix CVE-2022-4920?
To fix CVE-2022-4920, update Google Chrome to version 101.0.4951.41 or later.
3
What does CVE-2022-4920 exploit?
CVE-2022-4920 exploits a heap buffer overflow vulnerability in the Blink rendering engine of Google Chrome.
4
Can CVE-2022-4920 lead to a remote code execution?
Yes, CVE-2022-4920 could potentially allow for a sandbox escape via a crafted HTML page.
5
What versions of Google Chrome are affected by CVE-2022-4920?
Google Chrome versions prior to 101.0.4951.41 are affected by CVE-2022-4920.