CVE-2022-2294
published 2022-07-28CVE-2022-2294: Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…
PriorityP192high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-09-15
Exploited in the wild
EPSS
70.46%
99.3th percentile
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.6_and_ipados | — | — |
| apple | ipados | < 15.6 | 15.6 |
| apple | iphone_os | < 15.6 | 15.6 |
| apple | mac_os_x | < 10.15.7 | 10.15.7 |
| apple | mac_os_x | — | — |
| apple | macos | < 11.6.8 | 11.6.8 |
| apple | macos | >= 12.0 < 12.5 | 12.5 |
| apple | macos_monterey | — | — |
| apple | safari | — | — |
| apple | tvos | < 15.6 | 15.6 |
| apple | watchos | < 8.7 | 8.7 |
| chromium | chromium | >= 0 < 103.0.5060.114-1~deb11u1 | 103.0.5060.114-1~deb11u1 |
| chromium | chromium | >= 0 < 103.0.5060.114-1 | 103.0.5060.114-1 |
| chromium | chromium | >= 0 < 103.0.5060.114-1 | 103.0.5060.114-1 |
| chromium | chromium | >= 0 < 103.0.5060.114-1 | 103.0.5060.114-1 |
| debian | chromium | < chromium 103.0.5060.114-1 (bookworm) | chromium 103.0.5060.114-1 (bookworm) |
| debian | webkit2gtk | < chromium 103.0.5060.114-1 (bookworm) | chromium 103.0.5060.114-1 (bookworm) |
| debian | wpewebkit | < chromium 103.0.5060.114-1 (bookworm) | chromium 103.0.5060.114-1 (bookworm) |
| fedoraproject | extra_packages_for_enterprise_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 103.0.5060.114 | 103.0.5060.114 | |
| chrome | >= unspecified < 103.0.5060.114 | 103.0.5060.114 | |
| chrome_chrome | — | — | |
| msrc | microsoft_edge | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2022-2294 is a heap buffer overflow in the WebRTC component of Chrome (and Safari); exploitation is triggered via a crafted HTML page delivered to the victim's browser, enabling arbitrary code execution or denial-of-service ↗
- →The vulnerability resides specifically in the WebRTC component (Web Real-Time Communications) used for real-time audio/video in browsers; defenders should monitor for anomalous WebRTC traffic or browser crashes originating from untrusted web content ↗
- →CVE-2022-2294 was actively exploited in the wild as a zero-day; treat any unpatched Chrome for Android instance (prior to 103.0.5060.114) as a high-priority detection/hunting target ↗
- →CVE-2022-2294 was leveraged as part of Candiru DevilsTongue spyware delivery chains; hunt for DevilsTongue indicators on endpoints where Chrome for Android was unpatched during the exploitation window ↗
- →Safari 15.6 also patched CVE-2022-2294 in its WebRTC implementation; unpatched Safari instances processing maliciously crafted web content are also at risk of arbitrary code execution via memory corruption ↗
- ·Affected versions: Google Chrome prior to 103.0.5060.114 and Safari prior to 15.6 are vulnerable; patch to these versions or later to remediate CVE-2022-2294 ↗
- ·This was the fourth zero-day in Chrome in 2022 at time of disclosure, indicating active attacker interest in browser exploitation chains; prioritize patching accordingly ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9q96-cwq7-cr4m: Heap buffer overflow in WebRTC in Google Chrome prior to 103
ghsa_unreviewed·2022-07-29
CVE-2022-2294 [HIGH] CWE-787 GHSA-9q96-cwq7-cr4m: Heap buffer overflow in WebRTC in Google Chrome prior to 103
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
OSV
CVE-2022-2294: Heap buffer overflow in WebRTC in Google Chrome prior to 103
osv·2022-07-28·CVSS 8.8
CVE-2022-2294 [HIGH] CVE-2022-2294: Heap buffer overflow in WebRTC in Google Chrome prior to 103
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
VulnCheck
WebRTC Heap Buffer Overflow Vulnerability
vulncheck·2022·CVSS 8.8
CVE-2022-2294 [HIGH] CWE-122 WebRTC Heap Buffer Overflow Vulnerability
WebRTC Heap Buffer Overflow Vulnerability
WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome.
Affected: WebRTC WebRTC
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://decoded.avast.io/janvojtesek/the-return-of-candiru-zero-days-in-the-middle-east/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://raw.githubusercontent.com/blackorbird/APT_REPORT/master
Project0
Project Zero RCA: CVE-2022-2294: Heap buffer overflow in WebRTC
project_zero·CVSS 8.8
CVE-2022-2294 [HIGH] Project Zero RCA: CVE-2022-2294: Heap buffer overflow in WebRTC
# CVE-2022-2294: Heap buffer overflow in WebRTC
*Natalie Silvanovich, Project Zero*
## The Basics
**Disclosure or Patch Date:** July 4, 2022
**Product:** WebRTC (in-the-wild exploitation targeted Chrome)
**Advisory:**
* Chrome: https://chromereleases.googleblog.com/2022/07/stable-channel-update-for-desktop.html
* Safari: https://support.apple.com/en-us/HT213341
**Affected Versions:**
* WebRTC July 1, 2022 or earlier (WebRTC does not have formal versioning)
* Chrome pre-103.0.5060.114 and earlier
* Safari 15.5 and earlier
* This issue does not affect Firefox
The vulnerable library is also used by many mobile applications, but it is unclear whether the issue is exploitable. The bug is also only reachable in applications that use SDP munging or allow users to manipulate the SDP API. H
CISA
WebRTC Heap Buffer Overflow Vulnerability
cisa·2022-08-25·CVSS 8.8
CVE-2022-2294 [HIGH] CWE-122 WebRTC Heap Buffer Overflow Vulnerability
Vulnerability: WebRTC Heap Buffer Overflow Vulnerability
Affected: WebRTC WebRTC
WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome.
Required Action: Apply updates per vendor instructions.
Notes: https://groups.google.com/g/discuss-webrtc/c/5KBtZx2gvcQ; https://nvd.nist.gov/vuln/detail/CVE-2022-2294
Remediation Due Date: 2022-09-15
Ubuntu
WebKitGTK vulnerabilities
vendor_ubuntu·2022-08-15
CVE-2022-2294 WebKitGTK vulnerabilities
Title: WebKitGTK vulnerabilities
Summary: Several security issues were fixed in WebKitGTK.
Several security issues were discovered in the WebKitGTK Web and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK, such as Epiphany, to make all the necessary changes.
Apple
CVE-2022-2294: Safari 15.6
vendor_apple·2022-07-20·CVSS 8.8
CVE-2022-2294 [HIGH] CVE-2022-2294: Safari 15.6
Apple Security Update: About the security content of Safari 15.6
Product: Safari
Version: 15.6
CVE: CVE-2022-2294
Component: WebRTC
Impact: Processing maliciously crafted web content may lead to arbitrary code execution.
Description: A memory corruption issue was addressed with improved state management.
Apple
CVE-2022-2294: macOS Monterey 12.5
vendor_apple·2022-07-20·CVSS 8.8
CVE-2022-2294 [HIGH] CVE-2022-2294: macOS Monterey 12.5
Apple Security Update: About the security content of macOS Monterey 12.5
Product: macOS Monterey
Version: 12.5
CVE: CVE-2022-2294
Component: WebRTC
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A memory corruption issue was addressed with improved state management.
Apple
CVE-2022-2294: iOS 15.6 and iPadOS 15.6
vendor_apple·2022-07-20·CVSS 8.8
CVE-2022-2294 [HIGH] CVE-2022-2294: iOS 15.6 and iPadOS 15.6
Apple Security Update: About the security content of iOS 15.6 and iPadOS 15.6
Product: iOS 15.6 and iPadOS
Version: 15.6
CVE: CVE-2022-2294
Component: WebRTC
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A memory corruption issue was addressed with improved state management.
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2022-2294
vendor_chrome·2022-07-18·CVSS 8.8
CVE-2022-2294 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2022-2294
Long Term Support Channel Update for ChromeOS
CVE-2022-2294
Microsoft
Chromium: CVE-2022-2294 Heap buffer overflow in WebRTC
vendor_msrc·2022-07-12·CVSS 8.8
CVE-2022-2294 [HIGH] Chromium: CVE-2022-2294 Heap buffer overflow in WebRTC
Chromium: CVE-2022-2294 Heap buffer overflow in WebRTC
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
103.0.1264.49
7/6/2022
103.0.5060.114
Extended Stable: 102.0.1245.56
7/6/2022
102.0.5005.148
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longe
Debian
CVE-2022-2294: chromium - Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed ...
vendor_debian·2022·CVSS 8.8
CVE-2022-2294 [HIGH] CVE-2022-2294: chromium - Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed ...
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 103.0.5060.114-1)
bullseye: resolved (fixed in 103.0.5060.114-1~deb11u1)
forky: resolved (fixed in 103.0.5060.114-1)
sid: resolved (fixed in 103.0.5060.114-1)
trixie: resolved (fixed in 103.0.5060.114-1)
No detection rules found.
No public exploits indexed.
Greynoiseio
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates
blogs_greynoiseio·2026-02-02
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Qualys
The 9th Google Chrome Zero-Day Threat this Year – Again Just Before the Weekend
blogs_qualys·2022-12-03·CVSS 8.8
CVE-2022-4262 [HIGH] The 9th Google Chrome Zero-Day Threat this Year – Again Just Before the Weekend
## Table of Contents
Organizations respond, but slowly
Qualys Patch Management speeds remediation
Google has released yet another security update for the Chrome desktop web browser to address a high-severity vulnerability that is being exploited in the wild. This is the ninth Chrome zero-day fixed this year by Google. This security bug ( CVE-2022-4262 ; QID 377804 ) is a Type Confusion vulnerability in Chrome’s V8 JavaScript Engine.
Google has withheld details about the vulnerability to prevent expanding its malicious exploitation and to allow users time to apply the security updates necessary on their Chrome installations.
Google’s previous zero-days were also released right before a weekend (see Don’t spend another weekend patching Chrome and Don’t Spend Your Holiday Season Patching
Securelist
IT threat evolution in Q3 2022. Non-mobile statistics
blogs_securelist·2022-11-18
IT threat evolution in Q3 2022. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Number of users attacked by banking malware
TOP 10 banking malware families
Geography of financial malware attacks
Ransomware programs
Quarterly trends and highlights
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by criminals during cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
TOP 20 threats for macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks via web resources
Countries and territories that serve as sources of web-ba
Securelist
PC malware statistics, Q3 2022
blogs_securelist·2022-11-18
PC malware statistics, Q3 2022
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by criminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q3 2022
- IT threat evolution in Q3 2022. Non-mobile statistics
- IT threat evolution in Q3 2022. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q3 2022:
- Kaspersky solutions blocked 956,074,958 attacks from online resources across the globe.
- Web Anti-Virus recognized 251,288,987 unique URLs as malicious.
- Attempts to run malware fo
Qualys
July 2022 Patch Tuesday | Microsoft Releases 84 Vulnerabilities with 4 Critical, plus 2 Microsoft Edge (Chromium-Based) | Qualys
blogs_qualys·2022-07-12·CVSS 7.8
[HIGH] July 2022 Patch Tuesday | Microsoft Releases 84 Vulnerabilities with 4 Critical, plus 2 Microsoft Edge (Chromium-Based) | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- The July 2022 Microsoft Vulnerabilities Are Classified As Follows:
- Notable Microsoft Vulnerabilities Patched
- Microsoft Critical Vulnerability Highlights
- Microsoft Last But Not Least
- Adobe Security Bulletins and Advisories
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
- Rapid Response With Patch Management (PM)
- Qualys Monthly Webinar Series
- Join the Webinar This Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 84 vulnerabilities (aka flaws) in the July 2022 update, including four vulnerabilities classified as critical as they allow Remote Code Execution (RCE). This month’s Patch Tuesday cumulative Windows update includes the fix
Qualys
July 2022 Patch Tuesday | Microsoft Releases 84 Vulnerabilities With 4 Critical, Plus 2 Microsoft Edge (Chromium-Based); Adobe Releases 4 Advisories, 27 Vulnerabilities With 18 Critical.
blogs_qualys·2022-07-12·CVSS 7.8
[HIGH] July 2022 Patch Tuesday | Microsoft Releases 84 Vulnerabilities With 4 Critical, Plus 2 Microsoft Edge (Chromium-Based); Adobe Releases 4 Advisories, 27 Vulnerabilities With 18 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
The July 2022 Microsoft Vulnerabilities Are Classified As Follows:
Notable Microsoft Vulnerabilities Patched
Microsoft Critical Vulnerability Highlights
Microsoft Last But Not Least
Adobe Security Bulletins and Advisories
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
Rapid Response With Patch Management (PM)
Qualys Monthly Webinar Series
Join the Webinar This Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 84 vulnerabilities (aka flaws) in the July 2022 update, including four vulnerabilities classified as critical as they allow Remote Code Execution (RCE). This month’s Patch Tuesday cumulative Windows update includes the fix for one acti
Checkpoint
11th July – Threat Intelligence Report
blogs_checkpoint·2022-07-11
CVE-2022-30190 11th July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 11th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 11th July, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
An anonymous hacker identified as “ChinaDan” has claimed to have a stolen a database from the Shanghai National Police (SHGA) that includes sensitive data of 1 billion Chinese citizens, and offered to sell it for 10 bitcoins (approximately $200,000). He allegedly stole more than 22 terabytes of data including names, addresses,
Talos
Threat Source newsletter (July 7, 2022) — Teamwork makes the dream work
blogs_talos·2022-07-07
Threat Source newsletter (July 7, 2022) — Teamwork makes the dream work
Welcome to this week’s edition of the Threat Source newsletter.
I’ve been thinking a lot recently about the pros and cons of the way we publicize our threat research. I had a few conversations at Cisco Live with people — who are more generally IT-focused than hyper-focused on cybersecurity — about the amount of information we share on our blog and social media profiles. Our blog serves as the main mouthpiece for Talos, but I’m also always talking to our audience, directly or indirectly, through social media channels, our podcasts, or out in the world at conferences. But during these conversations, readers may wonder if we’re indirectly “helping” the bad guys by pointing out what they’re doing wrong or what we are doing to track them.
There will always be pros and cons to any type of disc
Talos
Threat Source newsletter (July 7, 2022) — Teamwork makes the dream work
blogs_talos·2022-07-07
Threat Source newsletter (July 7, 2022) — Teamwork makes the dream work
## Threat Source newsletter (July 7, 2022) — Teamwork makes the dream work
Welcome to this week’s edition of the Threat Source newsletter.
I’ve been thinking a lot recently about the pros and cons of the way we publicize our threat research. I had a few conversations at Cisco Live with people — who are more generally IT-focused than hyper-focused on cybersecurity — about the amount of information we share on our blog and social media profiles. Our blog serves as the main mouthpiece for Talos, but I’m also always talking to our audience, directly or indirectly, through social media channels, our podcasts, or out in the world at conferences. But during these conversations, readers may wonder if we’re indirectly “helping” the bad guys by pointing out what they’re doing wrong or what we are
Recorded Future
Tracking Candiru’s DevilsTongue Spyware in Multiple Countries
blogs_recorded_future
Tracking Candiru’s DevilsTongue Spyware in Multiple Countries
# Tracking Candiru’s DevilsTongue Spyware in Multiple Countries
Note: The analysis cut-off date for this report was June 26, 2025
## Executive Summary
Insikt Group identified new infrastructure associated with several clusters linked to the spyware vendor Candiru. This includes both victim-facing components likely used for deploying and controlling Candiru’s DevilsTongue spyware, as well as higher-tier operator infrastructure. DevilsTongue is a sophisticated, modular Windows malware. The clusters vary in design and administration, with some directly managing victim-facing systems, while others use intermediaries or the Tor network. Eight distinct clusters were identified, with five being likely still active, including those linked to Hungary and Saudi Arabia. One cluster tied to Indones
Recorded Future
Tracking Candiru’s DevilsTongue Spyware in Multiple Countries
blogs_recorded_future
Tracking Candiru’s DevilsTongue Spyware in Multiple Countries
## Tracking Candiru’s DevilsTongue Spyware in Multiple Countries
Note: The analysis cut-off date for this report was June 26, 2025
## Executive Summary
Insikt Group identified new infrastructure associated with several clusters linked to the spyware vendor Candiru. This includes both victim-facing components likely used for deploying and controlling Candiru’s DevilsTongue spyware, as well as higher-tier operator infrastructure. DevilsTongue is a sophisticated, modular Windows malware. The clusters vary in design and administration, with some directly managing victim-facing systems, while others use intermediaries or the Tor network. Eight distinct clusters were identified, with five being likely still active, including those linked to Hungary and Saudi Arabia. One cluster tied to Indone
http://www.openwall.com/lists/oss-security/2022/07/28/2https://chromereleases.googleblog.com/2022/07/stable-channel-update-for-desktop.htmlhttps://crbug.com/1341043https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5BQRTR4SIUNIHLLPWTGYSDNQK7DYCRSB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H2C4XOJVIILDXTOSMWJXHSQNEXFWSOD7/https://security.gentoo.org/glsa/202208-35https://security.gentoo.org/glsa/202208-39https://security.gentoo.org/glsa/202311-11http://www.openwall.com/lists/oss-security/2022/07/28/2https://chromereleases.googleblog.com/2022/07/stable-channel-update-for-desktop.htmlhttps://crbug.com/1341043https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5BQRTR4SIUNIHLLPWTGYSDNQK7DYCRSB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H2C4XOJVIILDXTOSMWJXHSQNEXFWSOD7/https://security.gentoo.org/glsa/202208-35https://security.gentoo.org/glsa/202208-39https://security.gentoo.org/glsa/202311-11https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-2294
2022-07-28
Published
2022-08-25
Added to CISA KEV
Exploited in the wild