CVE-2023-7024
Google Chromium WebRTC Heap Buffer Overflow Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 23 January 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 7.36% probability · 94th percentile
- CISA KEV
- Listed 2 January 2024 · due 23 January 2024
- Weakness
- CWE-787
- Affected
- google/chrome · debian/debian linux · fedoraproject/fedora
- Source
- chrome-cve-admin@google.com
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html; https://nvd.nist.gov/vuln/detail/CVE-2023-7024
References
- https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.htmlVendor Advisory
- https://crbug.com/1513170Exploit, Issue Tracking
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6M6AJDHUL6EDPURWQXGLUFJNDE7SOJT3/Broken Link, Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U6JL4VHZMHFGEGQYTF74533ZNRWMCMMR/Broken Link, Mailing List
- https://security.gentoo.org/glsa/202401-34Third Party Advisory
- https://www.debian.org/security/2023/dsa-5585Mailing List
- https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.htmlVendor Advisory
- https://crbug.com/1513170Exploit, Issue Tracking
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6M6AJDHUL6EDPURWQXGLUFJNDE7SOJT3/Broken Link, Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U6JL4VHZMHFGEGQYTF74533ZNRWMCMMR/Broken Link, Mailing List
- https://security.gentoo.org/glsa/202401-34Third Party Advisory
- https://www.debian.org/security/2023/dsa-5585Mailing List
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-7024US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.