CVE-2022-2294
HIGHCVSS 8.8Known ExploitedCISA Known Exploited Vulnerability
https://groups.google.com/g/discuss-webrtc/c/5KBtZx2gvcQ; https://nvd.nist.gov/vuln/detail/CVE-2022-2294
Remediation deadline: September 15, 2022
Ransomware use: Known
Description
WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome.
Timeline
Published:July 28th, 2022 2:15 AM
Last modified:August 4th, 2026 5:16 AM
Added to KEV:August 25th, 2022
CVSS Scoring
CVSS v3: 8.8 (HIGH)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Software
From NVD CPE configuration data
Vendors
googlefedoraprojectwebkitgtkwpewebkitapplewebrtc_project
Products
chromeextra_packages_for_enterprise_linuxfedorawebkitgtkwpe_webkitipadosiphone_osmac_os_xmacostvoswatchoswebrtc
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports
- http://www.openwall.com/lists/oss-security/2022/07/28/2Mailing List
- https://chromereleases.googleblog.com/2022/07/stable-channel-update-for-desktop.htmlRelease Notes
- https://crbug.com/1341043Permissions Required
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5BQRTR4SIUNIHLLPWTGYSDNQK7DYCRSB/Broken Link
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H2C4XOJVIILDXTOSMWJXHSQNEXFWSOD7/Broken Link
- https://security.gentoo.org/glsa/202208-35Third Party Advisory
- https://security.gentoo.org/glsa/202208-39Third Party Advisory
- https://security.gentoo.org/glsa/202311-11Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/07/28/2Mailing List
- https://chromereleases.googleblog.com/2022/07/stable-channel-update-for-desktop.htmlRelease Notes
- https://crbug.com/1341043Permissions Required
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5BQRTR4SIUNIHLLPWTGYSDNQK7DYCRSB/Broken Link
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H2C4XOJVIILDXTOSMWJXHSQNEXFWSOD7/Broken Link
- https://security.gentoo.org/glsa/202208-35Third Party Advisory
- https://security.gentoo.org/glsa/202208-39Third Party Advisory
- https://security.gentoo.org/glsa/202311-11Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-2294US Government Resource
Source: NIST NVD · Data may lag official sources by up to one minute