Junglewise Threat Intelligence

CVE-2023-7024: Google Chromium WebRTC Heap Buffer Overflow Vulnerability

CVE-2023-7024 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2024-01-02

Technologies: Google Chrome. Vendors: Google.

Executive brief

A heap buffer overflow vulnerability exists in the WebRTC component of Google Chromium-based browsers. A remote attacker can trigger heap corruption by enticing a user to visit a specially crafted HTML page, potentially leading to arbitrary code execution.

Affected products

  • Google Chrome prior to 120.0.6099.129
  • Google Chromium WebRTC

Timeline

  • 2023-12-20: patched: Stable channel update for desktop released (120.0.6099.129)
  • 2024-01-02: disclosed: CVE published and added to CISA KEV catalog
  • 2024-01-02: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-01-02: exploited: Reported as exploited in the wild in the advisory and CISA KEV catalog.