Executive brief
A heap buffer overflow vulnerability in WebRTC allows a remote attacker to perform shellcode execution or cause heap corruption via a specially crafted HTML page. The vulnerability has been observed being exploited in the wild and affects various web browsers and operating systems utilizing the WebRTC library.
Affected products
- WebRTC Project WebRTC
- Google Chrome prior to 103.0.5060.114
- Apple iPadOS up to (excluding) 15.6
- Apple iPhone OS up to (excluding) 15.6
Timeline
- 2022-07-04: patched: Google Chrome version 103.0.5060.114 released to address the vulnerability.
- 2022-08-25: disclosed: Vulnerability published and added to CISA Known Exploited Vulnerabilities catalog.
- 2022-08-25: kev added
- 2022-08-25: exploited: Reported as exploited in the wild.