PT-2022-3420 · Google+6 · Google Chrome+6

Jan Vojtesek

·

Published

2022-07-04

·

Updated

2025-12-08

·

CVE-2022-2294

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 103.0.5060.114
Description A heap buffer overflow issue in WebRTC allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This issue affects web browsers that use WebRTC, including Google Chrome. The vulnerability may allow an attacker to execute arbitrary code. It has been reported that this issue is being exploited in the wild, with threats including the use of watering hole techniques and the Devilstongue threat in various geographic locations such as Lebanon, Yemen, Turkey, and Palestine.
Recommendations For Google Chrome versions prior to 103.0.5060.114, update the browser to version 103.0.5060.114 or later to patch the vulnerability. As a temporary workaround, consider disabling WebRTC functionality until a patch is available. Restrict access to potentially vulnerable web pages to minimize the risk of exploitation. Avoid using crafted HTML pages that could trigger the heap buffer overflow issue until the browser is updated.

Fix

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2313
ALT-PU-2022-2314
ALT-PU-2022-2564
ALT-PU-2022-2611
ALT-PU-2022-2835
ALT-PU-2023-1462
BDU:2022-04198
CVE-2022-2294
DSA-5180-1
MGASA-2022-0287
OPENSUSE-SU-2022:10055-1
OPENSUSE-SU-2022:10057-1
OPENSUSE-SU-2022:10087-1
OPENSUSE-SU-2022:10088-1
OPENSUSE-SU-2022_10057-1
OPENSUSE-SU-2022_10087-1
OPENSUSE-SU-2022_10088-1
OPENSUSE-SU-2024:12180-1
OPENSUSE-SU-2024:12395-1
OPENSUSE-SU-2024:12948-1
USN-5568-1

Affected Products

Alt Linux
Astra Linux
Google Chrome
Linuxmint
Apple Macos
Suse
Ubuntu