CISA adds Google Chromium V8 Type Confusion bug to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-41993 | WebKit Code Execution Flaw in Apple iOS, iPadOS, macOS, and Safari Apple's WebKit engine, which renders web content for Safari and for essentially all HTML processing on iOS, iPadOS, and macOS, contains a flaw that leads to code execution when processing maliciously crafted web content. It is triggered when a user's browser or embedded web view loads attacker-controlled web content, so simply visiting a hostile page can be enough. Successful exploitation could allow arbitrary code execution within the affected application's context, a common stepping stone to broader device compromise. All users of Apple iOS, iPadOS, macOS, and Safari are potentially affected, as are users of non-Apple products that rely on WebKit for HTML processing. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-25, indicating confirmed in-the-wild exploitation; no public proof-of-concept is known. Do: Apply Apple's latest security updates for iOS, iPadOS, macOS, and Safari that patch WebKit, following the vendor instructions referenced by the CISA KEV entry, and treat unpatched WebKit builds as actively exploited. Until systems are patched, restrict exposure to untrusted web content (e.g., limit browsing and in-app web views to trusted sites for high-risk users). Also inventory any non-Apple applications or HTML-processing components in your environment that bundle WebKit and update them as their maintainers ship fixes. | 8.8 group max | 29% | KEV |
| mass1+ billion devices/users (WebKit ships in Safari and all web-content rendering on iOS, iPadOS, and macOS) | |
| CVE-2023-4762 | Chromium V8 Type Confusion (CVE-2023-4762) Enables RCE via Crafted Web Pages CVE-2023-4762 is a type confusion bug (CWE-843) in the V8 JavaScript engine used by Google Chromium, allowing a remote attacker to execute arbitrary code in the context of the browser when a user visits or is redirected to a crafted HTML page. Because V8 is shared across Chromium-based browsers, the flaw affects Google Chrome, Microsoft Edge, Opera, and other Chromium derivatives, not just Chrome itself. Successful exploitation gives an attacker code execution within the browser process on the victim's machine, a common foothold for delivering further malware. Google patched the bug in Chrome 116.0.5845.179/.180 (September 2023); any Chromium-based browser built on unpatched V8 remains vulnerable, and no public proof-of-concept is known. CISA added CVE-2023-4762 to the Known Exploited Vulnerabilities catalog on 2024-02-06, confirming exploitation in the wild (ransomware use unconfirmed), and EPSS assigns a ~41% probability of exploitation within 30 days (99th percentile). Do: Patch all Chromium-based browsers fleet-wide to Chrome 116.0.5845.179/.180 or later and each vendor's equivalent (current Edge, Opera, Brave, etc.), consistent with the CISA KEV required action to apply vendor mitigations or discontinue use. Verify Chromium/V8 browser versions in your endpoint inventory before and after rollout; since exploitation is triggered by a crafted web page, interim mitigations include restricting unpatched machines' browsing and warning users about unsolicited links. | 8.8 | 41% | KEV |
| massbillions of users (Chromium-based browsers dominate global usage; Chrome alone has ~3+ billion users) |
Full article285 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
February 07, 2024

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 Type Confusion bug to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 Type Confusion bug, tracked as CVE-2023-4762, to its Known Exploited Vulnerabilities (KEV) catalog.
The vulnerability impacts Google Chrome prior to 116.0.5845.179, it allows a remote attacker to execute arbitrary code via a crafted HTML page.
In September 2023, Citizen Lab and Google’s TAG revealed that the three recently patched Apple zero-days (CVE-2023-41993, CVE-2023-41991, CVE-2023-41992) were used to install Cytrox Predator spyware.
The experts reported that the exploit chain of the above flaws was delivered in two ways, one of them was exploiting CVE-2023-4762.
“The attacker also had an exploit chain to install Predator on Android devices in Egypt. TAG observed these exploits delivered in two different ways: the MITM injection and via one-time links sent directly to the target. We were only able to obtain the initial renderer remote code execution vulnerability for Chrome, which was exploiting CVE-2023-4762.” reads the analysis published by Google TAG. “We assess that Intellexa was also previously using this vulnerability as a 0-day.”
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this vulnerability by February 27, 2024.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – Hacking, Google Chromium)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/158820/security/cisa-adds-google-chromium-v8-type-confusion-bug-to-its-known-exploited-vulnerabilities-catalog.html