← KEV catalog
CISA known exploited vulnerability

CVE-2022-2294

WebRTC Heap Buffer Overflow Vulnerability

SOURCE FACT

WebRTC · WebRTC

WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome.

Required action

Apply updates per vendor instructions.

CISA notes

https://groups.google.com/g/discuss-webrtc/c/5KBtZx2gvcQ; https://nvd.nist.gov/vuln/detail/CVE-2022-2294

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?