Junglewise Threat Intelligence

CVE-2022-2294: WebRTC Heap Buffer Overflow Vulnerability

CVE-2022-2294 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-08-25

Technologies: Google Chrome, Apple Iphone Os, Apple iPadOS. Vendors: Google, Apple.

Executive brief

A heap buffer overflow vulnerability in WebRTC allows a remote attacker to perform shellcode execution or cause heap corruption via a specially crafted HTML page. The vulnerability has been observed being exploited in the wild and affects various web browsers and operating systems utilizing the WebRTC library.

Affected products

  • WebRTC Project WebRTC
  • Google Chrome prior to 103.0.5060.114
  • Apple iPadOS up to (excluding) 15.6
  • Apple iPhone OS up to (excluding) 15.6

Timeline

  • 2022-07-04: patched: Google Chrome version 103.0.5060.114 released to address the vulnerability.
  • 2022-08-25: disclosed: Vulnerability published and added to CISA Known Exploited Vulnerabilities catalog.
  • 2022-08-25: kev added
  • 2022-08-25: exploited: Reported as exploited in the wild.