ZeroHour

CVE-2022-2294

KEV ransomwaremass

Heap Buffer Overflow in Google Chrome WebRTC Exploited in the Wild

CISA: WebRTC Heap Buffer Overflow Vulnerability

CVSS 3.1
8.8 high
EPSS
70%p99
Published
()
KEV added
AI analysis

CVE-2022-2294 is a heap buffer overflow (out-of-bounds write, CWE-787) in the WebRTC component used by Google Chrome. A remote attacker can trigger the flaw by luring a user to a crafted HTML page, and successful exploitation allows heap corruption with potential arbitrary code execution (CVSS 3.1: 8.8, high impact on confidentiality, integrity and availability). It affects Chrome prior to 103.0.5060.114 and, because the vulnerable code path resides in the shared WebRTC/WebKit component, it also affects Apple's iPhone OS, iPadOS, macOS/Mac OS X, tvOS and watchOS, WebKitGTK, WPE WebKit, Fedora and Extra Packages for Enterprise Linux (EPEL), and the WebRTC project library itself. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-08-25 with known ransomware use, and reporting indicates mercenary spyware operators used it as a Chrome zero-day; EPSS places its 30-day exploitation probability at 70.5%. Google fixed the flaw in Chrome 103.0.5060.114, and Apple and the WebKit/WPE maintainers issued their own security updates for affected products.

What to do: Upgrade Google Chrome to 103.0.5060.114 or later on all managed and personal endpoints immediately. Apply Apple's released security updates for iPhone OS, iPadOS, macOS, tvOS and watchOS, and updated WebKitGTK, WPE WebKit and Fedora/EPEL packages for WebKit-based deployments. Given the CISA KEV listing, known ransomware use and 70.5% EPSS, prioritize patching and hunt for signs of exploitation (crafted-page lures and any linked spyware or ransomware activity) across browsers and WebKit applications.

Affected
google Chromeprior to 103.0.5060.114
webrtc project WebRTCaffected component library per CISA; fixed in updated releases
apple iPhone OSaffected releases; fixed via Apple security updates
apple iPadOSaffected releases; fixed via Apple security updates
apple macOS / Mac OS Xaffected releases; fixed via Apple security updates
apple tvOSaffected releases; fixed via Apple security updates
apple watchOSaffected releases; fixed via Apple security updates
WebKitGTKaffected releases; fixed in updated packages
wpewebkit WPE WebKitaffected releases; fixed in updated packages
fedoraproject Fedoraaffected releases; fixed via distribution package updates
fedoraproject Extra Packages for Enterprise Linux (EPEL)affected releases; fixed via distribution package updates
Estimated exposure
mass≈3+ billion Chrome users worldwide, plus additional users of Apple WebKit devices, WebKitGTK, WPE WebKit and Fedora/EPEL browser packages — Chrome holds roughly two-thirds of the global browser market (billions of users), and the vulnerable WebRTC component is also embedded in Apple WebKit, WebKitGTK, WPE WebKit and Fedora/EPEL browser builds, so the realistic exposure is at…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
WebRTC WebRTC
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
googlefedoraprojectwebkitgtkwpewebkitapplewebrtc project
Products
chrome, extra packages for enterprise linux, fedora, webkitgtk, wpe webkit, ipados, iphone os, mac os x, macos, tvos, watchos, webrtc
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news