CVE-2022-2294
KEV ransomwaremassHeap Buffer Overflow in Google Chrome WebRTC Exploited in the Wild
CISA: WebRTC Heap Buffer Overflow Vulnerability
CVE-2022-2294 is a heap buffer overflow (out-of-bounds write, CWE-787) in the WebRTC component used by Google Chrome. A remote attacker can trigger the flaw by luring a user to a crafted HTML page, and successful exploitation allows heap corruption with potential arbitrary code execution (CVSS 3.1: 8.8, high impact on confidentiality, integrity and availability). It affects Chrome prior to 103.0.5060.114 and, because the vulnerable code path resides in the shared WebRTC/WebKit component, it also affects Apple's iPhone OS, iPadOS, macOS/Mac OS X, tvOS and watchOS, WebKitGTK, WPE WebKit, Fedora and Extra Packages for Enterprise Linux (EPEL), and the WebRTC project library itself. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-08-25 with known ransomware use, and reporting indicates mercenary spyware operators used it as a Chrome zero-day; EPSS places its 30-day exploitation probability at 70.5%. Google fixed the flaw in Chrome 103.0.5060.114, and Apple and the WebKit/WPE maintainers issued their own security updates for affected products.
What to do: Upgrade Google Chrome to 103.0.5060.114 or later on all managed and personal endpoints immediately. Apply Apple's released security updates for iPhone OS, iPadOS, macOS, tvOS and watchOS, and updated WebKitGTK, WPE WebKit and Fedora/EPEL packages for WebKit-based deployments. Given the CISA KEV listing, known ransomware use and 70.5% EPSS, prioritize patching and hunt for signs of exploitation (crafted-page lures and any linked spyware or ransomware activity) across browsers and WebKit applications.
| google Chrome | prior to 103.0.5060.114 |
| webrtc project WebRTC | affected component library per CISA; fixed in updated releases |
| apple iPhone OS | affected releases; fixed via Apple security updates |
| apple iPadOS | affected releases; fixed via Apple security updates |
| apple macOS / Mac OS X | affected releases; fixed via Apple security updates |
| apple tvOS | affected releases; fixed via Apple security updates |
| apple watchOS | affected releases; fixed via Apple security updates |
| WebKitGTK | affected releases; fixed in updated packages |
| wpewebkit WPE WebKit | affected releases; fixed in updated packages |
| fedoraproject Fedora | affected releases; fixed via distribution package updates |
| fedoraproject Extra Packages for Enterprise Linux (EPEL) | affected releases; fixed via distribution package updates |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- Affected
- WebRTC WebRTC
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- googlefedoraprojectwebkitgtkwpewebkitapplewebrtc project
- Products
- chrome, extra packages for enterprise linux, fedora, webkitgtk, wpe webkit, ipados, iphone os, mac os x, macos, tvos, watchos, webrtc
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H