ZeroHour

CVE-2023-3079

KEV PoC mass

Type Confusion in Google Chromium V8 Engine Exploited in the Wild

CISA: Google Chromium V8 Type Confusion Vulnerability

CVSS 3.1
8.8 high
EPSS
32%p98
Published
()
KEV added
AI analysis

CVE-2023-3079 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine that powers Google Chromium, triggerable remotely when a user visits or is directed to a specially crafted HTML page. Successful exploitation causes heap corruption, which a remote attacker can leverage to execute code within the affected browser's renderer process. Every browser or application built on the Chromium engine is potentially affected, explicitly including Google Chrome, Microsoft Edge, and Opera. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-06-07 with a required action to apply vendor updates, and EPSS assigns a 32.1% probability of exploitation activity in the next 30 days (98th percentile). No public proof-of-concept code is known, but the KEV listing confirms real-world attacks, making rapid patching of all Chromium-based browsers a priority.

What to do: Immediately update Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers (including Chromium-embedded applications) to the latest vendor release, per the CISA KEV required action to apply updates per vendor instructions; confirm the update applied via the browser's About/Settings page. As a stopgap where patching is delayed, restrict browsing to trusted sites or disable JavaScript where feasible, since exploitation requires the renderer to process a crafted HTML page.

Affected
Google Chromium V8 engine
Google Chrome (Chromium-based)
Microsoft Edge (Chromium-based)
Opera browser (Chromium-based)
Estimated exposure
mass3+ billion users (Chrome's global install base alone; Chromium-based Edge and Opera add hundreds of millions more) — Chromium is the world's dominant browser engine, with Google Chrome's user base on the order of billions and Chromium-based Edge and Opera adding hundreds of millions more, so exposure plausibly spans effectively all Chromium browser…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlefedoraprojectdebianapplelinuxcouchbase
Products
chrome, fedora, debian linux, macos, linux kernel, couchbase server
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news