← All CVEs

CVE-2022-2294

high · 8.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-08-25Remediation due 2022-09-15

Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

8.8
CVSS
70.5%
EPSS (exploit prob.)
99th
EPSS percentile
2022-07-28
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-787

Affected products

VendorProductAffected versions
googlechrome< 103.0.5060.114
fedoraprojectextra_packages_for_enterprise_linux8.0
fedoraprojectfedora35
fedoraprojectfedora36
webkitgtkwebkitgtk< 2.36.5
wpewebkitwpe_webkit< 2.36.5
appleipados< 15.6
appleiphone_os< 15.6
applemac_os_x< 10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemacos< 11.6.8
applemacos>= 12.0, < 12.5
appletvos< 15.6
applewatchos< 8.7
webrtc_projectwebrtcall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-2294