Widevine is a digital rights management framework deployed across a narrow but strategically important set of trusted applications embedded in content-delivery systems and media players. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, concentrated in the trusted application component and recurrently rooted in integer overflow and wraparound conditions that can compromise media encryption boundaries. Defenders should prioritize patching for this vendor given the severity profile of its disclosures; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Widevine over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-48336CRITICAL Widevine Trusted Application (TA) 5.0.0 through 7.1.1 has a PRDiagParseAndStoreData integer overflow and resultant buffer overflow. | Jun 26, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-48332CRITICAL Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_save_keys file_name_len integer overflow and resultant buffer overflow. | Jun 26, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-48335CRITICAL Widevine Trusted Application (TA) 5.0.0 through 7.1.1 has a PRDiagVerifyProvisioning integer overflow and resultant buffer overflow. | Jun 26, 2023 | 9.8 | 27 | NO | NO |
CVE-2022-48334CRITICAL Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_verify_keys total_len+file_name_len integer overflow and resultant buffer overflow. | Jun 26, 2023 | 9.8 | 27 | NO | NO |
CVE-2022-48333CRITICAL Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_verify_keys prefix_len+feature_name_len integer overflow and resultant buffer overflow. | Jun 26, 2023 | 9.8 | 27 | NO | NO |
CVE-2022-48331CRITICAL Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_save_keys feature_name_len integer overflow and resultant buffer overflow. | Jun 26, 2023 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Widevine.
Media articles that mention a CVE ID that affects a product developed by Widevine — matched by CVE ID, not by vendor name.