CVE-2022-2294
WebRTC Heap Buffer Overflow Vulnerability
CVSS
8.8
High
EPSS
70.5%
p99
KEV
YES
Aug 25, 2022
Exploit Today
80
0-100
Published: Jul 28, 2022 · Last modified: Aug 4, 2026 · CWE-787
Product
WebRTC / WebRTC
Vulnerability
WebRTC Heap Buffer Overflow Vulnerability
Added to KEV
Aug 25, 2022
Remediate by
Sep 15, 2022
Known ransomware use
Yes
Summary description
WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome.
Required action
Apply updates per vendor instructions.
Notes
https://groups.google.com/g/discuss-webrtc/c/5KBtZx2gvcQ; https://nvd.nist.gov/vuln/detail/CVE-2022-2294
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2022/07/28/2
- chromereleases.googleblog.comhttps://chromereleases.googleblog.com/2022/07/stable-channel-update-for-desktop.html
- crbug.comhttps://crbug.com/1341043
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5BQRTR4SIUNIHLLPWTGYSDNQK7DYCRSB/
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H2C4XOJVIILDXTOSMWJXHSQNEXFWSOD7/
- security.gentoo.orghttps://security.gentoo.org/glsa/202208-35
- security.gentoo.orghttps://security.gentoo.org/glsa/202208-39
- security.gentoo.orghttps://security.gentoo.org/glsa/202311-11
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2022/07/28/2
- chromereleases.googleblog.comhttps://chromereleases.googleblog.com/2022/07/stable-channel-update-for-desktop.html
- crbug.comhttps://crbug.com/1341043
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5BQRTR4SIUNIHLLPWTGYSDNQK7DYCRSB/
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H2C4XOJVIILDXTOSMWJXHSQNEXFWSOD7/
- security.gentoo.orghttps://security.gentoo.org/glsa/202208-35
- security.gentoo.orghttps://security.gentoo.org/glsa/202208-39
- security.gentoo.orghttps://security.gentoo.org/glsa/202311-11
- www.cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-2294