CVE-2022-2294

unknown KEV
Published 2022-08-25 · Modified 2022-08-25
CVSS v3
CVSS v2
VIR risk
1.5

Description

WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome.

CISA KEV

Vendor
WebRTC
Product
WebRTC
Due date
2022-09-15

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://groups.google.com/g/discuss-webrtc/c/5KBtZx2gvcQ; https://nvd.nist.gov/vuln/detail/CVE-2022-2294

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2022-2294

Exploits

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed103.0.5060.114-1
debian debianbullseyefixed103.0.5060.114-1~deb11u1
debian debianforkyfixed103.0.5060.114-1
debian debiansidfixed103.0.5060.114-1
debian debiantrixiefixed103.0.5060.114-1

References

Verify integrity in audit chain (admin only). AS-IS.