Vulnerability record · CVE-2022-2294 · published 28 July 2022
CVE-2022-2294: Google Chrome WebRTC heap buffer overflow via crafted HTML page
Google · Chrome
CVE-2022-2294 is a heap buffer overflow in the WebRTC component of Google Chrome prior to 103.0.5060.114. A remote attacker can trigger heap corruption by getting a victim to load a crafted HTML page. The flaw is an out-of-bounds write (CWE-787) and affects WebRTC-derived code shipped in Chrome, Fedora, WebKitGTK, WPE WebKit, and Apple operating systems.
Description
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe vulnerability is in CISA's KEV catalog with known ransomware campaign use and a very high EPSS score, and it allows remote heap corruption with high impact.
What it is
CVE-2022-2294 is a heap buffer overflow in the WebRTC component of Google Chrome prior to 103.0.5060.114. A remote attacker can trigger heap corruption by getting a victim to load a crafted HTML page. The flaw is an out-of-bounds write (CWE-787) and affects WebRTC-derived code shipped in Chrome, Fedora, WebKitGTK, WPE WebKit, and Apple operating systems.
Impact
Successful exploitation can corrupt the heap and potentially lead to code execution in the context of the browser or affected application. The CVSS 3.1 vector rates confidentiality, integrity, and availability impact as high.
Attack surface
Reached over the network through a crafted HTML page rendered by the affected browser or WebRTC-enabled component. No privileges are required, but user interaction (loading the page) is required per the CVSS vector.
Exploitation
CVE-2022-2294 is listed in CISA's Known Exploited Vulnerabilities catalog with a due date of 2022-09-15 and is flagged for known ransomware campaign use. EPSS gives a 30-day exploitation probability of 0.70461 (99.355th percentile), indicating active exploitation is likely.
What to do
- Update Google Chrome to 103.0.5060.114 or later, and apply the corresponding vendor updates for Fedora, WebKitGTK, WPE WebKit, and Apple operating systems.
- Prioritize patching internet-facing and user-facing browser endpoints, since exploitation requires only a crafted page.
- Enforce automatic browser updates and verify version compliance across managed endpoints.
- Restrict or disable WebRTC in environments where it is not required, if operationally feasible.
- Monitor CISA KEV guidance and apply updates per vendor instructions by the stated due date.
Detection
- Monitor for browser crashes or heap corruption indicators in Chrome and WebRTC-enabled applications.
- Review proxy and network logs for access to suspicious or newly registered domains serving crafted HTML.
- Track endpoint telemetry for unexpected child processes or code execution originating from browser processes.
- Check installed Chrome and WebKit versions against 103.0.5060.114 and vendor-patched builds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-2294 to the Known Exploited Vulnerabilities catalog on 25 August 2022 as "WebRTC Heap Buffer Overflow Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 15 September 2022.
Affected products
12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-2294 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-2294), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.