Security
Loading…

CVE-2022-2294

HIGHCVSS 8.8Known Exploited
Description

WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome.

Timeline
Published:July 28th, 2022 2:15 AM
Last modified:August 4th, 2026 5:16 AM
Added to KEV:August 25th, 2022
CVSS Scoring

CVSS v3: 8.8 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

googlefedoraprojectwebkitgtkwpewebkitapplewebrtc_project

Products

chromeextra_packages_for_enterprise_linuxfedorawebkitgtkwpe_webkitipadosiphone_osmac_os_xmacostvoswatchoswebrtc
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

Source: NIST NVD · Data may lag official sources by up to one minute