CVE-2022-4920: Google Chrome

Critical severity, CVSS 9.6. EPSS: 0.8% chance of exploitation in the next 30 days.

Heap buffer overflow in Blink in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Affected products

  • Google Chrome: before 101.0.4951.41 (fixed in 101.0.4951.41)

Published 2023-07-29. Last modified 2026-06-17.