Security News > 2023 > September > Yet another Chrome zero-day exploited in the wild! (CVE-2023-5217)

Yet another Chrome zero-day exploited in the wild! (CVE-2023-5217)
2023-09-28 11:46

Google has fixed another critical zero-day vulnerability in Chrome that is being exploited in the wild.

The vulnerability is caused by a heap buffer overflow in vp8 encoding in libvpx - a video codec library from Google and the Alliance for Open Media.

CVE-2023-5217 has been fixed in Google Chrome 117.0.5938.132 for Windows, Mac and Linux users.

"Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven't yet fixed," Google said.

The vulnerability has been reported by Clément Lecigne of Google's Threat Analysis Group on September 25.

CVE-2023-41064 - a buffer overflow vulnerability in the ImageI/O framework - turned out to be the effectively the same flaw as CVE-2023-4863 - a Chrome zero-day heap buffer overflow vulnerability in WebP, because the source of the vulnerability is the libwebp library both companies implemented.


News URL

https://www.helpnetsecurity.com/2023/09/28/cve-2023-5217/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2023-09-28 CVE-2023-5217 Out-of-bounds Write vulnerability in multiple products
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
8.8
2023-09-12 CVE-2023-4863 Out-of-bounds Write vulnerability in multiple products
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
8.8
2023-09-07 CVE-2023-41064 Classic Buffer Overflow vulnerability in Apple Ipados and Iphone OS
A buffer overflow issue was addressed with improved memory handling.
local
low complexity
apple CWE-120
7.8