HIGH
CVE-2022-2294
CVSS
8.8
KEV
Description
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Summary dbcve.org
Heap buffer overflow vulnerability in Google Chrome's WebRTC (Web Real-Time Communication) component allows a remote attacker to potentially exploit heap corruption by tricking users into visiting a crafted HTML page. The vulnerability affects versions prior to 103.0.5060.114 and could lead to arbitrary code execution or system compromise.
Mitigation
Update Google Chrome to version 103.0.5060.114 or later to patch the WebRTC heap buffer overflow vulnerability.
Weakness (CWE)
CWE-787
Out-of-bounds Write
EPSS Score
70.46%
Probability of exploitation in next 30 days
99.4th percentile
References
http://www.openwall.com/lists/oss-security/2022/07/28/2
Mailing List, Third Party Advisory
https://chromereleases.googleblog.com/2022/07/stable-channel-update-for-desktop.html
Release Notes, Vendor Advisory
https://crbug.com/1341043
Permissions Required
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5BQRTR4SIUNIHLLPWTGYSDNQK7DYCRSB/
Broken Link
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H2C4XOJVIILDXTOSMWJXHSQNEXFWSOD7/
Broken Link
https://security.gentoo.org/glsa/202208-35
Third Party Advisory
https://security.gentoo.org/glsa/202208-39
Third Party Advisory
https://security.gentoo.org/glsa/202311-11
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-2294
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.