← Back to browse · API

CVE-2022-2294

Severity
HIGH
CVSS
8.8
EPSS
0.70461
Risk score
84.86
CISA KEV
Yes
PoC
No
Published
2022-08-25
Modified
2022-08-25
First seen
2026-08-05
Aliases
EUVD-2022-34567, GHSA-9Q96-CWQ7-CR4M
Products
Google:Chrome unspecified <103.0.5060.114, WebRTC:WebRTC, apple:ipados, apple:iphone_os, apple:mac_os_x, apple:macos, apple:tvos, apple:watchos, fedoraproject:extra_packages_for_enterprise_linux, fedoraproject:fedora, google:chrome, webkitgtk:webkitgtk, webrtc_project:webrtc, wpewebkit:wpe_webkit
Sources
nvd CVE-2022-2294
euvd EUVD-2022-34567
cisa.gov CVE-2022-2294

Description

WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome.

References