CVE-2022-2294: WebRTC Heap Buffer Overflow Vulnerability
AMD. A memory corruption issue was addressed with improved input validation.
Other sources
APFS. The issue was addressed with improved memory handling.
— Apple
Apple Neural Engine. An integer overflow was addressed with improved input validation.
— Apple
Apple Neural Engine. An out-of-bounds read was addressed with improved bounds checking.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
Apple Neural Engine. This issue was addressed with improved checks.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 12.5 - Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 103.0.5060.114 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 15.6 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 15.6 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 15.6
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-42858
- CVE-2022-32832
- CVE-2022-32788
- CVE-2022-32880
- CVE-2022-32826
- CVE-2022-42805
- CVE-2022-32948
- CVE-2022-32810
- CVE-2022-32840
- CVE-2022-32845
- CVE-2022-48578
- CVE-2022-32797
- CVE-2022-32851
- CVE-2022-32852
- CVE-2022-32853
- CVE-2022-32831
- CVE-2022-32910
- CVE-2022-32820
- CVE-2022-32825
- CVE-2022-32789
- CVE-2022-32805
- CVE-2022-32828
- CVE-2022-32839
- CVE-2022-32819
- CVE-2022-32793
- CVE-2022-32821
- CVE-2022-32849
- CVE-2022-32787
- CVE-2022-32897
- CVE-2022-32802
- CVE-2022-32841
- CVE-2022-32785
- CVE-2022-32811
- CVE-2022-32812
- CVE-2022-48503
- CVE-2022-32813
- CVE-2022-32815
- CVE-2022-32817
- CVE-2022-32829
- CVE-2022-26981
- CVE-2022-32823
- CVE-2022-32814
- CVE-2022-32786
- CVE-2022-32800
- CVE-2022-32838
- CVE-2022-32843
- CVE-2022-46708
- CVE-2022-32796
- CVE-2022-32842
- CVE-2022-32798
- CVE-2022-32799
- CVE-2022-32818
- CVE-2022-32857
- CVE-2022-32807
- CVE-2022-32801
- CVE-2021-28544
- CVE-2022-24070
- CVE-2022-29046
- CVE-2022-29048
- CVE-2022-32834
- CVE-2022-32933
- CVE-2022-32885
- CVE-2022-32861
- CVE-2022-32863
- CVE-2022-32816
- CVE-2022-32792
- CVE-2022-2294
- CVE-2022-32860
- CVE-2022-32837
- CVE-2022-32847
- CVE-2022-32848
- CVE-2022-2295
- CVE-2022-2296
- CVE-2022-32784
- CVE-2022-32824
- CVE-2022-32855
- CVE-2022-32830
- CVE-2022-26768
- CVE-2022-32844
Frequently Asked Questions
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2022-2294.
What is the title of this vulnerability?
The title of this vulnerability is WebRTC Heap Buffer Overflow Vulnerability.
What is the impact of this vulnerability?
This vulnerability allows an attacker to perform shellcode execution.
Which software is affected by this vulnerability?
Web browsers using WebRTC, including Google Chrome, Apple macOS Monterey (up to version 12.5), Apple iOS (up to version 15.6), Apple iPadOS (up to version 15.6), and Apple Safari (up to version 15.6).
Are there any references related to this vulnerability?
Yes, you can find references related to this vulnerability at the following links: [Link 1](https://groups.google.com/g/discuss-webrtc/c/5KBtZx2gvcQ), [Link 2](https://support.apple.com/en-us/HT213345), [Link 3](https://support.apple.com/en-us/HT213341).
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-119.