Heap-based buffer overflow in Google Chrome - CVE-2022-2294

 

Heap-based buffer overflow in Google Chrome - CVE-2022-2294

Published: July 4, 2022 / Updated: July 21, 2022


Vulnerability identifier: #VU64910
CSH Severity: Critical
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2294
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within WebRTC implementation. A remote attacker can trick the victim ti visit a specially crafted website, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Google Chrome
Apple Safari
Microsoft Edge
Gentoo Linux
Fedora
macOS
Apple iOS
iPadOS
Ubuntu
Chrome OS
Dell Hybrid Client
WPE WebKit
WebKitGTK+
Google Chrome for Android
chromium (Debian package)
libjavascriptcoregtk-4.0-18 (Ubuntu package)
libwebkit2gtk-4.0-37 (Ubuntu package)
net-libs/webkit-gtk
dev-qt/qtwebengine
chromium
www-client/microsoft-edge
www-client/chromium
www-client/chromium-bin
www-client/google-chrome
libwebkit2gtk-4.1-0 (Ubuntu package)

How to mitigate CVE-2022-2294

Install updates from vendor's website.

Google Chrome - addressed in versions 102.0.5005.148, 103.0.5060.114
WPE WebKit - update to 2.36.5
WebKitGTK+ - update to 2.36.5
macOS - update to 12.5 21G72
Apple Safari - update to 15.6
Apple iOS - update to 15.6 19G71
iPadOS - update to 15.6 19G71
Google Chrome for Android - update to 103.0.5060.71
chromium (Debian package) - update to 103.0.5060.114-1~deb11u1
Microsoft Edge - update to 103.0.1264.49
libjavascriptcoregtk-4.0-18 (Ubuntu package) - addressed in versions 2.36.6-0ubuntu0.20.04.1, 2.36.6-0ubuntu0.22.04.1
libwebkit2gtk-4.0-37 (Ubuntu package) - addressed in versions 2.36.6-0ubuntu0.20.04.1, 2.36.6-0ubuntu0.22.04.1
libwebkit2gtk-4.1-0 (Ubuntu package) - update to 2.36.6-0ubuntu0.22.04.1
net-libs/webkit-gtk - update to 2.36.7
Chrome OS - update to 102.0.5005.153
dev-qt/qtwebengine - update to 103.0.5060.53
chromium - addressed in versions 103.0.5060.114-1.el7, 103.0.5060.114-1.el8, 103.0.5060.114-1.el9, 103.0.5060.114-1.fc35, 103.0.5060.114-1.fc36
www-client/microsoft-edge - update to 104.0.1293.63
www-client/chromium - update to 104.0.5112.101
www-client/chromium-bin - update to 104.0.5112.101
www-client/google-chrome - update to 104.0.5112.101

External References

Related Security Bulletins