HIGH

CVE-2023-7024

Google Chrome 2023-12-21 CVSS v3.1
CVSS
8.8
KEV

Description

Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Summary dbcve.org

Heap buffer overflow vulnerability in WebRTC component of Google Chrome allows remote attackers to corrupt heap memory via malicious HTML pages. The flaw exists in versions prior to 120.0.6099.129 and could enable code execution or denial of service.

Mitigation

Update Google Chrome to version 120.0.6099.129 or later. Organizations should deploy browser updates through their patch management infrastructure.

Proof of Concept

Weakness (CWE)

CWE-787 Out-of-bounds Write

EPSS Score

7.36%
Probability of exploitation in next 30 days
94.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE