Releases43
Frequency2 months 2 weeks
Last Release
TypeScript definitions for webrtc

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
all versions8.8 HIGH

Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

< 3.0.155.3 MEDIUM5 MEDIUM

Pion WebRTC before 3.0.15 didn't properly tear down the DTLS Connection when certificate verification failed. The PeerConnectionState was set to failed, but a user could ignore that and continue to use the PeerConnection. )A WebRTC implementation shouldn't allow the user to continue if verification has failed.)