CISA KEV · Known exploitedHigh

CVE-2022-2294

Google Chrome, chrome, extra packages for enterprise linux

Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS
8.8
EPSS
70.5%
99.3% percentile
CISA KEV
Listed
Published
2022.07.28
PRIORITY ASSESSMENT

Immediate review

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.

Known exploitationConfirmed by CISA KEV
Exploit probability70.5%
Technical severityCVSS 8.8

Vulnerability overview

Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Affected product and versions

Product
Google Chrome, chrome, extra packages for enterprise linux
Affected versions
>= unspecified < 103.0.5060.114, < 103.0.5060.114, 8.0, 35, 36, < 2.36.5, < 15.6, < 10.15.7, 10.15.7, < 11.6.8, >= 12.0 < 12.5, < 8.7
Fixed versions
103.0.5060.114, 2.36.5, 15.6, 10.15.7, 11.6.8, 12.5, 8.7

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
CISA required action

Apply updates per vendor instructions.

Due date: 2022.09.15
  1. 1
    Identify

    Confirm that Google Chrome, chrome, extra packages for enterprise linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE
CWE-122, CWE-787
KEV added
2022.08.25
Ransomware use
확인됨