HIGH
CVE-2023-7024
CVSS
8.8
KEV
Description
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Summary dbcve.org
Heap buffer overflow vulnerability in WebRTC component of Google Chrome allows remote attackers to corrupt heap memory via malicious HTML pages. The flaw exists in versions prior to 120.0.6099.129 and could enable code execution or denial of service.
Mitigation
Update Google Chrome to version 120.0.6099.129 or later. Organizations should deploy browser updates through their patch management infrastructure.
Weakness (CWE)
CWE-787
Out-of-bounds Write
EPSS Score
7.36%
Probability of exploitation in next 30 days
94.2th percentile
References
https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html
Vendor Advisory
https://crbug.com/1513170
Exploit, Issue Tracking
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6M6AJDHUL6EDPURWQXGLUFJNDE7SOJT3/
Broken Link, Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U6JL4VHZMHFGEGQYTF74533ZNRWMCMMR/
Broken Link, Mailing List
https://security.gentoo.org/glsa/202401-34
Third Party Advisory
https://www.debian.org/security/2023/dsa-5585
Mailing List
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-7024
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.