CVE-2022-2294High· 8.8▾ Abyssal⚠ Exploited in the wild0dayHeap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 48.4 · likelihood 14.1 · exploitation 25 · ransomware 5
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Sep 15, 2022
Last analysed / modified upstream
70%
Added to the CISA catalog on Aug 25, 2022. Federal remediation due Sep 15, 2022. View catalog ↗
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
chrome < 103.0.5060.114extra_packages_for_enterprise_linux = 8.0fedora = 35fedora = 36webkitgtk < 2.36.5wpe_webkit < 2.36.5ipados < 15.6iphone_os < 15.6mac_os_x < 10.15.7mac_os_x = 10.15.7macos < 11.6.8macos >= 12.0, < 12.5tvos < 15.6watchos < 8.7webrtcUpgrade past the affected range:
chrome 103.0.5060.114webkitgtk 2.36.5wpe_webkit 2.36.5ipados 15.6iphone_os 15.6mac_os_x 10.15.7macos 12.5tvos 15.6watchos 8.7Connected by shared product, vendor, weakness, or advisory.
CVE-2026-87491High· 8.8Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
CVE-2026-2441High· 8.8Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
CVE-2025-14174High· 8.8Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page
CVE-2026-91711High· 8.8Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
CVE-2026-85046High· 8.8Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
CVE-2026-19148High· 8.3Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page