ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Google Patches Chrome Zero

criticalVulnerability exploited in the wildimportance 60CVE-2023-5217CVE-2023-5186CVE-2023-5187

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-5186
+1 in the same advisory: …5187
Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to engage in specific UI interaction to pote

Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: High)

NVD description · AI analysis pending
8.8<1%
  • google chrome
  • google debian linux
  • google fedora
CVE-2023-5217
Heap Buffer Overflow in Google Chromium libvpx (CVE-2023-5217) Added to CISA KEV

CVE-2023-5217 is a heap buffer overflow (CWE-787) in the VP8 encoding path of libvpx, the open-source video codec library bundled with Google's Chromium/Chrome browser. A remote attacker can trigger the flaw by luring a user to a crafted HTML page whose web content invokes the vulnerable VP8 encoding code, corrupting the heap and potentially achieving code execution in the affected browser. Anyone running Google Chrome/Chromium — or other browsers and software that embed libvpx, as CISA notes the library's use is 'not limited to Google Chrome' — is affected. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2023-10-02 (ransomware association: unknown), though no public proof-of-concept is available and a CVSS score has not been published; EPSS puts the 30-day exploitation probability at 49% (99th percentile). Defenders should treat this as an actively exploited browser vulnerability requiring prompt patching.

Do: Update Chrome/Chromium to the vendor release that fixes CVE-2023-5217 — Google shipped the fix with its late-September 2023 stable-channel security update, so verify the exact build number in Google's advisory (it is not specified in the source data). Also patch any other products bundling libvpx (other browsers, media/ffmpeg-based tooling) per vendor instructions, and ensure KEV compliance by applying the required mitigations or discontinuing use of affected builds by the CISA deadline.

8.849% KEV PoC
  • Google Chromium libvpx (VP8 encoding component, as bundled in Chrome/Chromium)
  • Google Chrome (browser shipping Chromium libvpx)
masson the order of 1–3+ billion users/devices (Chrome's global installed base; roughly two-thirds desktop browser market share)
Full article314 words · extracted from infosecurity-magazine.com · click to collapse

Google has patched three high-severity flaws in the latest release of its Chrome browser, including one zero-day vulnerability it said is being actively exploited in the wild.

Google Chrome 117.0.5938.132 is currently rolling out worldwide to Windows, Mac and Linux users in the Stable desktop channel.

Most noteworthy is a fix for CVE-2023-5217, described as a heap buffer overflow issue in the VP8 encoding of open source libvpx video codec library.

No other details were available on the official Google Chrome update page, although the firm said “access to bug details and links may be kept restricted until a majority of users are updated with a fix.”

However, we do know that it was reported by Clément Lecigne of Google’s Threat Analysis Group (TAG) on Monday. The quick turnaround time for a patch signifies the criticality of the bug.

That was confirmed by TAG researcher, Maddie Stone, who said the vulnerability is “in use by a commercial surveillance vendor.”

Read more on spyware: NSO Group's Pegasus Spyware Found on High-Risk iPhones

It’s unclear exactly who that vendor is at this stage, but there has been a spate of zero-day discoveries of late tied back to commercial spyware makers.

Just last week, Apple patched three zero-day vulnerabilities it claimed may have been actively exploited in the wild on iOS devices. These were discovered by TAG and the non-profit Citizen Lab.

Citizen Lab tied the bugs to Cytrox’s Predator spyware and said they were delivered via links sent on SMS and WhatsApp. They were initially observed targeting Egyptian presidential hopeful, Ahmed Eltantawy.

A previous duo of Apple zero-days used in a “BlastPass” exploit chain were traced to the NSO Group and its Pegasus spyware.

The remaining two high-severity bugs fixed in this Chrome update are CVE-2023-5186, a use-after-free flaw in Passwords, and CVE-2023-5187, a use-after-free bug in Extensions.

Editorial image credit: NiP STUDIO / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/google-patches-chrome-zero-day-1/