Executive brief
A heap buffer overflow vulnerability exists in the WebRTC component of Google Chromium-based browsers. A remote attacker can trigger heap corruption by enticing a user to visit a specially crafted HTML page, potentially leading to arbitrary code execution.
Affected products
- Google Chrome prior to 120.0.6099.129
- Google Chromium WebRTC
Timeline
- 2023-12-20: patched: Stable channel update for desktop released (120.0.6099.129)
- 2024-01-02: disclosed: CVE published and added to CISA KEV catalog
- 2024-01-02: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-01-02: exploited: Reported as exploited in the wild in the advisory and CISA KEV catalog.