cbcvebase.
CVE-2023-5217
published 2023-09-28

CVE-2023-5217: Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap…

PriorityP190high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-10-23
Exploited in the wild
EPSS
49.01%
98.8th percentile
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Affected

56 ranges· showing 25
VendorProductVersion rangeFixed in
appleios_16.7.1_and_ipados
appleios_17.0.3_and_ipados
appleipados
appleipados>= 17.0 < 17.0.317.0.3
appleiphone_os
appleiphone_os>= 17.0 < 17.0.317.0.3
chromiumchromium>= 0 < 117.0.5938.132-1~deb11u1117.0.5938.132-1~deb11u1
chromiumchromium>= 0 < 117.0.5938.132-1~deb12u1117.0.5938.132-1~deb12u1
chromiumchromium>= 0 < 117.0.5938.132-1117.0.5938.132-1
chromiumchromium>= 0 < 117.0.5938.132-1117.0.5938.132-1
debianchromium< chromium 117.0.5938.132-1~deb12u1 (bookworm)chromium 117.0.5938.132-1~deb12u1 (bookworm)
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianfirefox< chromium 117.0.5938.132-1~deb12u1 (bookworm)chromium 117.0.5938.132-1~deb12u1 (bookworm)
debianfirefox-esr< chromium 117.0.5938.132-1~deb12u1 (bookworm)chromium 117.0.5938.132-1~deb12u1 (bookworm)
debianlibvpx< chromium 117.0.5938.132-1~deb12u1 (bookworm)chromium 117.0.5938.132-1~deb12u1 (bookworm)
debianthunderbird< chromium 117.0.5938.132-1~deb12u1 (bookworm)chromium 117.0.5938.132-1~deb12u1 (bookworm)
electronelectron>= 0 < 22.3.2522.3.25
electronelectron>= 24.0.0 < 24.8.524.8.5
electronelectron>= 25.0.0 < 25.8.425.8.4
electronelectron>= 26.0.0 < 26.2.426.2.4
electronelectron>= 27.0.0-alpha.1 < 27.0.0-beta.827.0.0-beta.8
fedoraprojectfedora
fedoraprojectfedora

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2023-5217 is a heap buffer overflow in the VP8 encoding feature of the libvpx library; any product using libvpx for VP8/VP9 encoding/decoding is potentially affected, not just Chrome
  • The vulnerability is triggered via an attacker-controlled VP8 media stream delivered to the content process; monitor for unexpected VP8 stream processing leading to heap corruption
  • CVE-2023-5217 has been exploited in the wild by commercial spyware vendors in targeted attacks; prioritize detection on endpoints used by high-risk individuals such as journalists and opposition politicians
  • CVE-2023-5217 was exploited to install spyware; correlate with Google TAG reporting on Cytrox Predator spyware delivery chains
  • Microsoft Edge is also affected by CVE-2023-5217 via its libvpx dependency; ensure Edge is patched and monitor for exploitation
  • Exploitation vector is a crafted HTML page; web-based delivery via malicious or compromised sites should be considered in threat hunting
  • ·Fixed in Google Chrome 117.0.5938.132 and libvpx 1.13.1; versions prior to these are vulnerable
  • ·CVE-2023-5217 is primarily a client-side vulnerability; server-side exploitation is unlikely unless the workload handles video (e.g., virtual desktops, video processing servers, build environments)
  • ·No concrete public details about the specific malicious activity or exploit payload had been published as of October 1, 2023; bug details were kept restricted by Google pending broad patch rollout

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ghsa8.8HIGH
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.