Junglewise Threat Intelligence

CVE-2023-3079: Google Chromium V8 Type Confusion Vulnerability

CVE-2023-3079 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2023-06-07

Technologies: Google Chromium V8, Google Chrome. Vendors: Google.

Executive brief

A type confusion vulnerability in the V8 engine of Google Chromium allows a remote attacker to exploit heap corruption via a specially crafted HTML page. This vulnerability is known to be exploited in the wild and affects various Chromium-based browsers and downstream applications.

Affected products

  • Google Chrome prior to 114.0.5735.110
  • Couchbase Couchbase Server up to (excluding) 7.1.5, 7.2.0
  • Fedora Project Fedora 37, 38

Timeline

  • 2023-06-07: disclosed
  • 2023-06-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-06-07: advisory: NVD publication date

Related threats