Umbra Wiki cve cve/CVE-2022-2294
Back to wiki

CVE-2022-2294 — WebRTC Heap Buffer Overflow Vulnerability

provenance: imported · CVE: CVE-2022-2294

CVE-2022-2294: WebRTC Heap Buffer Overflow Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project WebRTC
Product WebRTC
Date added 2022-08-25
Due date 2022-09-15
Ransomware campaign use Known

Description

WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://groups.google.com/g/discuss-webrtc/c/5KBtZx2gvcQ; https://nvd.nist.gov/vuln/detail/CVE-2022-2294

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-2294
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog