ZeroHour

CVE-2023-2033

KEVmass

Type Confusion in Google Chromium V8 Engine Exploited in the Wild

CISA: Google Chromium V8 Type Confusion Vulnerability

CVSS 3.1
8.8 high
EPSS
41%p99
Published
()
KEV added
AI analysis

CVE-2023-2033 is a type confusion flaw (CWE-843) in Google's Chromium V8 JavaScript engine that a remote attacker can trigger by convincing a user to load a crafted HTML page. Successful exploitation could lead to heap corruption in the browser, potentially allowing the attacker to execute code in the context of the affected browser. Because V8 underpins the entire Chromium ecosystem, users of Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browser or application are potentially affected. The flaw is already being exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-04-17, and EPSS assigns a 40.8% probability of exploitation within 30 days (99th percentile), though no public proof-of-concept is known and ransomware use is unknown.

What to do: Update Google Chrome and every other Chromium-based browser in use (Microsoft Edge, Opera, Brave, etc.) to the latest vendor-supplied stable release, per CISA's KEV required action to apply updates per vendor instructions. Verify installed browser versions across managed endpoints and treat unpatched Chromium builds as actively exploited given the KEV listing and high EPSS score.

Affected
Google Chromium V8 engine
Google Chrome (Chromium-based browser)
Microsoft Edge (Chromium-based browser)
Opera (Chromium-based browser)
Estimated exposure
massbillions of users (Chrome alone has roughly 3 billion users; Chromium also powers Edge, Opera, Brave and many embedded applications) — The Chromium engine holds dominant browser market share, with Google Chrome's global install base measured in billions and Microsoft Edge, Opera, Brave and numerous embedded/Electron applications sharing the same V8 code, so the plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googledebianfedoraprojectcouchbase
Products
chrome, debian linux, fedora, couchbase server
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news