cbcvebase.
CVE-2022-2294
published 2022-07-28

CVE-2022-2294: Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-09-15
Exploited in the wild
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
appleios_15.6_and_ipados
appleipados< 15.615.6
appleiphone_os< 15.615.6
applemac_os_x< 10.15.710.15.7
applemac_os_x
applemacos< 11.6.811.6.8
applemacos>= 12.0 < 12.512.5
applemacos_monterey
applesafari
appletvos< 15.615.6
applewatchos< 8.78.7
chromiumchromium>= 0 < 103.0.5060.114-1~deb11u1103.0.5060.114-1~deb11u1
chromiumchromium>= 0 < 103.0.5060.114-1103.0.5060.114-1
chromiumchromium>= 0 < 103.0.5060.114-1103.0.5060.114-1
chromiumchromium>= 0 < 103.0.5060.114-1103.0.5060.114-1
debianchromium< chromium 103.0.5060.114-1 (bookworm)chromium 103.0.5060.114-1 (bookworm)
debianwebkit2gtk< chromium 103.0.5060.114-1 (bookworm)chromium 103.0.5060.114-1 (bookworm)
debianwpewebkit< chromium 103.0.5060.114-1 (bookworm)chromium 103.0.5060.114-1 (bookworm)
fedoraprojectextra_packages_for_enterprise_linux
fedoraprojectfedora
fedoraprojectfedora
googlechrome< 103.0.5060.114103.0.5060.114
googlechrome>= unspecified < 103.0.5060.114103.0.5060.114
googlechrome_chrome
msrcmicrosoft_edge

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH