ZeroHour

CVE-2023-7024

KEV PoC mass1

Actively Exploited Heap Buffer Overflow in Google Chrome WebRTC (CVE-2023-7024)

CISA: Google Chromium WebRTC Heap Buffer Overflow Vulnerability

CVSS 3.1
8.8 high
EPSS
7%p94
Published
()
KEV added
AI analysis

CVE-2023-7024 is a high-severity heap buffer overflow (CWE-787) in the WebRTC component of Google Chrome/Chromium. A remote attacker can trigger it by convincing a user to open a crafted HTML page (user interaction is required per the CVSS score), causing memory corruption in the browser. Successful exploitation can crash the browser or potentially allow arbitrary code execution, with high impact on confidentiality, integrity, and availability. Anyone running Google Chrome prior to 120.0.6099.129 is affected, as are users of Chromium builds packaged by Debian and Fedora. The flaw is being exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-02, and Google addressed it as an actively exploited zero-day — with an EPSS probability of ~7.4% of exploitation within 30 days (94th percentile).

What to do: Update Google Chrome to 120.0.6099.129 or later immediately (verify via chrome://settings/help, since many installs auto-update but require a relaunch); organizations on Debian or Fedora should apply their distribution's patched chromium security update. Per CISA KEV requirements, federal agencies must apply vendor mitigations or discontinue use of affected builds by the required deadline. Until patched, avoid opening untrusted web pages, as exploitation requires user interaction with crafted HTML content.

Affected
google Chrome (Chromium browser)All versions prior to 120.0.6099.129
Debian Linux (chromium package)Chromium builds prior to 120.0.6099.129; fixed via Debian security updates
fedoraproject Fedora (chromium package)Chromium builds prior to 120.0.6099.129; fixed via Fedora security updates
Estimated exposure
mass≈3 billion+ users/installs (Chrome's global install base) — Chrome is the world's dominant browser with roughly 60%+ market share across desktop and mobile (an install base in the billions per public market-share scans), and Chromium packages shipped by Debian and Fedora extend exposure to Linux…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CISA Known Exploited Vulnerability
Affected
Google Chromium WebRTC
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
googledebianfedoraproject
Products
chrome, debian linux, fedora
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news