Junglewise Threat Intelligence

CVE-2023-2033: Google Chromium V8 Type Confusion Vulnerability

CVE-2023-2033 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2023-04-17

Technologies: Google Chromium V8, Microsoft Edge, Opera Software Opera, Google Chrome. Vendors: Google, Microsoft, Opera Software.

Executive brief

A type confusion vulnerability in the Google Chromium V8 engine allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability has been observed being exploited in the wild.

Affected products

  • Google Chrome prior to 112.0.5615.121
  • Microsoft Edge
  • Opera Software Opera
  • Couchbase Couchbase Server up to (excluding) 7.1.5, 7.2.0

Timeline

  • 2023-04-14: patched: Stable channel update for desktop released.
  • 2023-04-17: disclosed: Vulnerability published and added to CISA KEV catalog.
  • 2023-04-17: kev added
  • 2023-04-17: exploited: Reported as exploited in the wild.

Related threats