Google discovers another Chrome zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-7024 | Actively Exploited Heap Buffer Overflow in Google Chrome WebRTC (CVE-2023-7024) CVE-2023-7024 is a high-severity heap buffer overflow (CWE-787) in the WebRTC component of Google Chrome/Chromium. A remote attacker can trigger it by convincing a user to open a crafted HTML page (user interaction is required per the CVSS score), causing memory corruption in the browser. Successful exploitation can crash the browser or potentially allow arbitrary code execution, with high impact on confidentiality, integrity, and availability. Anyone running Google Chrome prior to 120.0.6099.129 is affected, as are users of Chromium builds packaged by Debian and Fedora. The flaw is being exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-02, and Google addressed it as an actively exploited zero-day — with an EPSS probability of ~7.4% of exploitation within 30 days (94th percentile). Do: Update Google Chrome to 120.0.6099.129 or later immediately (verify via chrome://settings/help, since many installs auto-update but require a relaunch); organizations on Debian or Fedora should apply their distribution's patched chromium security update. Per CISA KEV requirements, federal agencies must apply vendor mitigations or discontinue use of affected builds by the required deadline. Until patched, avoid opening untrusted web pages, as exploitation requires user interaction with crafted HTML content. | 8.8 | 7% | KEV PoC |
| mass≈3 billion+ users/installs (Chrome's global install base) |
Full article272 words · extracted from therecord.media · click to collapse
Google Chrome has released an emergency security fix for a zero-day flaw that has been exploited in the wild. This vulnerability, tracked as CVE-2023-7024, affects the desktop versions of the browser on Mac, Linux and Windows. It is the eighth actively exploited zero-day in Chrome discovered since the start of 2023. Clément Lecigne and Vlad Stolyarov of Google's Threat Analysis Group first reported it on December 19. Not many details are available about the flaw, except that it was found in WebRTC, an open-source project that provides web browsers and mobile applications with real-time communication via simple application programming interfaces (APIs). The security update fixes a potential heap buffer overflow in WebRTC. Such flaws can occur in a specific part of the memory allocation of a computer program. Google hasn't provided any details about specific attacks that exploit the vulnerability. It is also not clear if any users were directly affected by its exploitation. The CVSS (сommon vulnerability scoring system) assessing the severity of this bug is not yet available. "Access to bug details and links may be kept restricted until a majority of users are updated with a fix," Google said. Chrome vulnerabilities often rise to a level of severity that prompts Google to issue a patch as soon as one is ready, instead of waiting for the next regular update cycle. Earlier in November, Google released an update to address a severe vulnerability that affected 2D graphics-rendering code known as Skia. This bug was also exploited in the wild. In October, the company issued fixes for a bug in an open-source tool known as libvpx, used in video encoding.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/google-chrome-zero-day-patch-webrtc