cbcvebase.
CVE-2022-2294
published 2022-07-28

CVE-2022-2294: Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

PriorityP192high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-09-15
Exploited in the wild
EPSS
70.46%
99.3th percentile
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
appleios_15.6_and_ipados
appleipados< 15.615.6
appleiphone_os< 15.615.6
applemac_os_x< 10.15.710.15.7
applemac_os_x
applemacos< 11.6.811.6.8
applemacos>= 12.0 < 12.512.5
applemacos_monterey
applesafari
appletvos< 15.615.6
applewatchos< 8.78.7
chromiumchromium>= 0 < 103.0.5060.114-1~deb11u1103.0.5060.114-1~deb11u1
chromiumchromium>= 0 < 103.0.5060.114-1103.0.5060.114-1
chromiumchromium>= 0 < 103.0.5060.114-1103.0.5060.114-1
chromiumchromium>= 0 < 103.0.5060.114-1103.0.5060.114-1
debianchromium< chromium 103.0.5060.114-1 (bookworm)chromium 103.0.5060.114-1 (bookworm)
debianwebkit2gtk< chromium 103.0.5060.114-1 (bookworm)chromium 103.0.5060.114-1 (bookworm)
debianwpewebkit< chromium 103.0.5060.114-1 (bookworm)chromium 103.0.5060.114-1 (bookworm)
fedoraprojectextra_packages_for_enterprise_linux
fedoraprojectfedora
fedoraprojectfedora
googlechrome< 103.0.5060.114103.0.5060.114
googlechrome>= unspecified < 103.0.5060.114103.0.5060.114
googlechrome_chrome
msrcmicrosoft_edge

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2022-2294 is a heap buffer overflow in the WebRTC component of Chrome (and Safari); exploitation is triggered via a crafted HTML page delivered to the victim's browser, enabling arbitrary code execution or denial-of-service
  • The vulnerability resides specifically in the WebRTC component (Web Real-Time Communications) used for real-time audio/video in browsers; defenders should monitor for anomalous WebRTC traffic or browser crashes originating from untrusted web content
  • CVE-2022-2294 was actively exploited in the wild as a zero-day; treat any unpatched Chrome for Android instance (prior to 103.0.5060.114) as a high-priority detection/hunting target
  • CVE-2022-2294 was leveraged as part of Candiru DevilsTongue spyware delivery chains; hunt for DevilsTongue indicators on endpoints where Chrome for Android was unpatched during the exploitation window
  • Safari 15.6 also patched CVE-2022-2294 in its WebRTC implementation; unpatched Safari instances processing maliciously crafted web content are also at risk of arbitrary code execution via memory corruption
  • ·Affected versions: Google Chrome prior to 103.0.5060.114 and Safari prior to 15.6 are vulnerable; patch to these versions or later to remediate CVE-2022-2294
  • ·This was the fourth zero-day in Chrome in 2022 at time of disclosure, indicating active attacker interest in browser exploitation chains; prioritize patching accordingly

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.