CISA Known Exploited Vulnerability

CVE-2022-2294 Ransomware

WebRTC · WebRTC

WebRTC Heap Buffer Overflow Vulnerability

Date added
BOD 22-01 due date
CWE CWE-122
Ransomware Known

CISA description

WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome.

Required action

Apply updates per vendor instructions.