ZeroHour

CVE-2023-5217

KEV PoC mass1

Heap Buffer Overflow in Google Chromium libvpx (CVE-2023-5217) Added to CISA KEV

CISA: Google Chromium libvpx Heap Buffer Overflow Vulnerability

CVSS 3.1
8.8 high
EPSS
49%p99
Published
()
KEV added
AI analysis

CVE-2023-5217 is a heap buffer overflow (CWE-787) in the VP8 encoding path of libvpx, the open-source video codec library bundled with Google's Chromium/Chrome browser. A remote attacker can trigger the flaw by luring a user to a crafted HTML page whose web content invokes the vulnerable VP8 encoding code, corrupting the heap and potentially achieving code execution in the affected browser. Anyone running Google Chrome/Chromium — or other browsers and software that embed libvpx, as CISA notes the library's use is 'not limited to Google Chrome' — is affected. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2023-10-02 (ransomware association: unknown), though no public proof-of-concept is available and a CVSS score has not been published; EPSS puts the 30-day exploitation probability at 49% (99th percentile). Defenders should treat this as an actively exploited browser vulnerability requiring prompt patching.

What to do: Update Chrome/Chromium to the vendor release that fixes CVE-2023-5217 — Google shipped the fix with its late-September 2023 stable-channel security update, so verify the exact build number in Google's advisory (it is not specified in the source data). Also patch any other products bundling libvpx (other browsers, media/ffmpeg-based tooling) per vendor instructions, and ensure KEV compliance by applying the required mitigations or discontinuing use of affected builds by the CISA deadline.

Affected
Google Chromium libvpx (VP8 encoding component, as bundled in Chrome/Chromium)
Google Chrome (browser shipping Chromium libvpx)
Estimated exposure
masson the order of 1–3+ billion users/devices (Chrome's global installed base; roughly two-thirds desktop browser market share) — Chrome/Chromium's dominant browser market share (public market-share trackers put Chrome around 65% of desktop traffic) means virtually every internet-facing desktop fleet ships the vulnerable libvpx library, with additional exposure from…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CISA Known Exploited Vulnerability
Affected
Google Chromium libvpx
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
webmprojectmicrosoftmozillafedoraprojectdebianapplegoogleredhat
Products
libvpx, edge, edge chromium, firefox, thunderbird, fedora, debian linux, ipados, iphone os, chrome, enterprise linux
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news