CVE-2023-5217
published 2023-09-28CVE-2023-5217: Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap…
PriorityP190high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-10-23
Exploited in the wild
EPSS
49.01%
98.8th percentile
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_16.7.1_and_ipados | — | — |
| apple | ios_17.0.3_and_ipados | — | — |
| apple | ipados | — | — |
| apple | ipados | >= 17.0 < 17.0.3 | 17.0.3 |
| apple | iphone_os | — | — |
| apple | iphone_os | >= 17.0 < 17.0.3 | 17.0.3 |
| chromium | chromium | >= 0 < 117.0.5938.132-1~deb11u1 | 117.0.5938.132-1~deb11u1 |
| chromium | chromium | >= 0 < 117.0.5938.132-1~deb12u1 | 117.0.5938.132-1~deb12u1 |
| chromium | chromium | >= 0 < 117.0.5938.132-1 | 117.0.5938.132-1 |
| chromium | chromium | >= 0 < 117.0.5938.132-1 | 117.0.5938.132-1 |
| debian | chromium | < chromium 117.0.5938.132-1~deb12u1 (bookworm) | chromium 117.0.5938.132-1~deb12u1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | < chromium 117.0.5938.132-1~deb12u1 (bookworm) | chromium 117.0.5938.132-1~deb12u1 (bookworm) |
| debian | firefox-esr | < chromium 117.0.5938.132-1~deb12u1 (bookworm) | chromium 117.0.5938.132-1~deb12u1 (bookworm) |
| debian | libvpx | < chromium 117.0.5938.132-1~deb12u1 (bookworm) | chromium 117.0.5938.132-1~deb12u1 (bookworm) |
| debian | thunderbird | < chromium 117.0.5938.132-1~deb12u1 (bookworm) | chromium 117.0.5938.132-1~deb12u1 (bookworm) |
| electron | electron | >= 0 < 22.3.25 | 22.3.25 |
| electron | electron | >= 24.0.0 < 24.8.5 | 24.8.5 |
| electron | electron | >= 25.0.0 < 25.8.4 | 25.8.4 |
| electron | electron | >= 26.0.0 < 26.2.4 | 26.2.4 |
| electron | electron | >= 27.0.0-alpha.1 < 27.0.0-beta.8 | 27.0.0-beta.8 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2023-5217 is a heap buffer overflow in the VP8 encoding feature of the libvpx library; any product using libvpx for VP8/VP9 encoding/decoding is potentially affected, not just Chrome ↗
- →The vulnerability is triggered via an attacker-controlled VP8 media stream delivered to the content process; monitor for unexpected VP8 stream processing leading to heap corruption ↗
- →CVE-2023-5217 has been exploited in the wild by commercial spyware vendors in targeted attacks; prioritize detection on endpoints used by high-risk individuals such as journalists and opposition politicians ↗
- →CVE-2023-5217 was exploited to install spyware; correlate with Google TAG reporting on Cytrox Predator spyware delivery chains ↗
- →Microsoft Edge is also affected by CVE-2023-5217 via its libvpx dependency; ensure Edge is patched and monitor for exploitation ↗
- →Exploitation vector is a crafted HTML page; web-based delivery via malicious or compromised sites should be considered in threat hunting ↗
- ·Fixed in Google Chrome 117.0.5938.132 and libvpx 1.13.1; versions prior to these are vulnerable ↗
- ·CVE-2023-5217 is primarily a client-side vulnerability; server-side exploitation is unlikely unless the workload handles video (e.g., virtual desktops, video processing servers, build environments) ↗
- ·No concrete public details about the specific malicious activity or exploit payload had been published as of October 1, 2023; bug details were kept restricted by Google pending broad patch rollout ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ghsa8.8HIGH
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric EcoStruxure Power Operation (Update A)
cisa_ics·2026-02-26·CVSS 9.8
[CRITICAL] Schneider Electric EcoStruxure Power Operation (Update A)
ICS Advisory
##
Schneider Electric EcoStruxure Power Operation (Update A)
Last RevisedFebruary 26, 2026
Alert CodeICSA-25-203-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Successful exploitation of these vulnerabilities could result in the loss of system functionality or unauthorized access to system functions.
The following versions of Schneider Electric EcoStruxure Power Operation (Update A) are affected:
- EcoStruxure Power Operation (EPO) 2022 <=CU6 (CVE-2023-50447, CVE-2024-28219, CVE-2022-45198, CVE-2023-5217, CVE-2023-35945, CVE-2023-44487)
- EcoStruxure Power Operation (EPO) 2024 <=CU1 (CVE-2023-50447, CVE-2024-28219, CVE-2022-45198, CVE-2023-5217, CVE-2023-35945, CVE-2023-44487)
CVS
Ubuntu
libvpx vulnerability
vendor_ubuntu·2024-12-18
CVE-2023-5217 libvpx vulnerability
Title: libvpx vulnerability
Summary: libvpx could be made to crash or run programs if it received specially
crafted input.
It was discovered that libvpx did not properly handle certain malformed
media files. If an application using libvpx opened a specially crafted
file, a remote attacker could cause a denial of service, or possibly
execute arbitrary code. Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 16.04 LTS were previously addressed in USN-6403-1,
USN-6403-2, and USN-6403-3. This update addresses the issue in Ubuntu 14.04
LTS.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
libvpx vulnerabilities
vendor_ubuntu·2023-11-01
CVE-2023-44488 libvpx vulnerabilities
Title: libvpx vulnerabilities
Summary: Several security issues were fixed in libvpx.
USN-6403-1 fixed several vulnerabilities in libvpx. This update provides
the corresponding update for Ubuntu 16.04 LTS.
Original advisory details:
It was discovered that libvpx did not properly handle certain malformed
media files. If an application using libvpx opened a specially crafted
file, a remote attacker could cause a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
libvpx vulnerabilities
vendor_ubuntu·2023-10-23
CVE-2023-5217 libvpx vulnerabilities
Title: libvpx vulnerabilities
Summary: Several security issues were fixed in libvpx.
USN-6403-1 fixed several vulnerabilities in libvpx. This update provides
the corresponding update for Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that libvpx did not properly handle certain malformed
media files. If an application using libvpx opened a specially crafted
file, a remote attacker could cause a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Firefox regressions
vendor_ubuntu·2023-10-11·CVSS 6.5
[MEDIUM] Firefox regressions
Title: Firefox regressions
Summary: USN-6404-1 caused some minor regressions in Firefox.
USN-6404-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-5169,
CVE-2023-5170, CVE-2023-5171, CVE-2023-5172, CVE-2023-5175, CVE-2023-5176)
Ronald Crane discovered that Firefox did not properly manage memory when
non-HTTPS Alternate Services (network.http.altsvc.oe) is enabled. An
attacker could poten
Apple
CVE-2023-5217: iOS 16.7.1 and iPadOS 16.7.1
vendor_apple·2023-10-10·CVSS 8.8
CVE-2023-5217 [HIGH] CVE-2023-5217: iOS 16.7.1 and iPadOS 16.7.1
Apple Security Update: About the security content of iOS 16.7.1 and iPadOS 16.7.1
Product: iOS 16.7.1 and iPadOS
Version: 16.7.1
CVE: CVE-2023-5217
Component: CVE-2023-5217
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2023-5217
vendor_chrome·2023-10-06·CVSS 8.8
CVE-2023-5217 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2023-5217
Long Term Support Channel Update for ChromeOS
CVE-2023-5217
Apple
CVE-2023-5217: iOS 17.0.3 and iPadOS 17.0.3
vendor_apple·2023-10-04·CVSS 8.8
CVE-2023-5217 [HIGH] CVE-2023-5217: iOS 17.0.3 and iPadOS 17.0.3
Apple Security Update: About the security content of iOS 17.0.3 and iPadOS 17.0.3
Product: iOS 17.0.3 and iPadOS
Version: 17.0.3
CVE: CVE-2023-5217
Component: CVE-2023-5217
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2023-10-03·CVSS 8.8
CVE-2023-5176 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2023-4057, CVE-2023-4577,
CVE-2023-4578, CVE-2023-4583, CVE-2023-4585, CVE-2023-5169, CVE-2023-5171,
CVE-2023-5176)
Andrew McCreight discovered that Thunderbird did not properly manage during
the worker lifecycle. An attacker could potentially exploit this issue to
cause a denial of service. (CVE-2023-3600)
Harveer Singh discovered that Thunderbird did not store push n
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2023-10-03·CVSS 6.5
CVE-2023-5175 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-5169,
CVE-2023-5170, CVE-2023-5171, CVE-2023-5172, CVE-2023-5175, CVE-2023-5176)
Ronald Crane discovered that Firefox did not properly manage memory when
non-HTTPS Alternate Services (network.http.altsvc.oe) is enabled. An
attacker could potentially exploit this issue to cause a denial of service.
(CVE-2023-5173)
Clément Lecigne discovered that Firefox did not properly manage memory when
handling VP8 media stream. An attacker-contr
Ubuntu
libvpx vulnerabilities
vendor_ubuntu·2023-10-02
CVE-2023-44488 libvpx vulnerabilities
Title: libvpx vulnerabilities
Summary: Several security issues were fixed in libvpx.
It was discovered that libvpx did not properly handle certain malformed
media files. If an application using libvpx opened a specially crafted
file, a remote attacker could cause a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
CISA
Google Chromium libvpx Heap Buffer Overflow Vulnerability
cisa·2023-10-02·CVSS 8.8
CVE-2023-5217 [HIGH] CWE-787 Google Chromium libvpx Heap Buffer Overflow Vulnerability
Vulnerability: Google Chromium libvpx Heap Buffer Overflow Vulnerability
Affected: Google Chromium libvpx
Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html; https://nvd.nist.gov/vuln/detail/CVE-2023-5217
Remediation Due Date: 2023-10-23
Red Hat
libvpx: Heap buffer overflow in vp8 encoding in libvpx
vendor_redhat·2023-09-27·CVSS 8.8
CVE-2023-5217 [HIGH] CWE-119 libvpx: Heap buffer overflow in vp8 encoding in libvpx
libvpx: Heap buffer overflow in vp8 encoding in libvpx
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
A heap-based buffer overflow flaw was found in the way libvpx, a library used to process VP8 and VP9 video codecs data, processes certain specially formatted video data via a crafted HTML page. This flaw allows an attacker to crash or remotely execute arbitrary code in an application, such as a web browser that is compiled with this library.
Statement: This security issue has been classified as having an Important security impact. Desktop users are at a high risk of exploitation of this flaw with very mini
Microsoft
Chromium: CVE-2023-5217 Heap buffer overflow in vp8 encoding in libvpx
vendor_msrc·2023-09-12·CVSS 8.8
CVE-2023-5217 [HIGH] Chromium: CVE-2023-5217 Heap buffer overflow in vp8 encoding in libvpx
Chromium: CVE-2023-5217 Heap buffer overflow in vp8 encoding in libvpx
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Google is aware that an exploit for CVE-2023-5217 exists in the wild.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-
Debian
CVE-2023-5217: chromium - Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5...
vendor_debian·2023·CVSS 8.8
CVE-2023-5217 [HIGH] CVE-2023-5217: chromium - Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5...
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 117.0.5938.132-1~deb12u1)
bullseye: resolved (fixed in 117.0.5938.132-1~deb11u1)
forky: resolved (fixed in 117.0.5938.132-1)
sid: resolved (fixed in 117.0.5938.132-1)
trixie: resolved (fixed in 117.0.5938.132-1)
Mozilla
Mozilla Foundation Security Advisory 2023-44: CVE-2023-5217
vendor_mozilla·CVSS 8.8
CVE-2023-5217 [HIGH] Mozilla Foundation Security Advisory 2023-44: CVE-2023-5217
Mozilla Foundation Security Advisory 2023-44
CVE: CVE-2023-5217
Product: Firefox, Firefox ESR, Firefox Focus for Android, Firefox for Android, Thunderbird
Impact: critical
Fixed in: Firefox 118.0.1
Firefox ESR 115.3.1
Firefox Focus for Android 118.1
Firefox for Android 118.1
Thunderbird 115.3.1
OSV
firefox regressions
osv·2023-10-11·CVSS 6.5
CVE-2023-5169 [MEDIUM] firefox regressions
firefox regressions
USN-6404-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-5169,
CVE-2023-5170, CVE-2023-5171, CVE-2023-5172, CVE-2023-5175, CVE-2023-5176)
Ronald Crane discovered that Firefox did not properly manage memory when
non-HTTPS Alternate Services (network.http.altsvc.oe) is enabled. An
attacker could potentially exploit this issue to cause a denial of service.
(CVE-2023-5173
GHSA
CefSharp affected by libvpx's heap buffer overflow in vp8 encoding
ghsa·2023-10-05·CVSS 8.8
CVE-2023-5217 [HIGH] CefSharp affected by libvpx's heap buffer overflow in vp8 encoding
CefSharp affected by libvpx's heap buffer overflow in vp8 encoding
Google is aware that an exploit for CVE-2023-5217 exists in the wild.
Description
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
References
- https://www.cve.org/CVERecord?id=CVE-2023-5217
- https://nvd.nist.gov/vuln/detail/CVE-2023-5217
OSV
CefSharp affected by libvpx's heap buffer overflow in vp8 encoding
osv·2023-10-05·CVSS 8.8
CVE-2023-5217 [HIGH] CefSharp affected by libvpx's heap buffer overflow in vp8 encoding
CefSharp affected by libvpx's heap buffer overflow in vp8 encoding
Google is aware that an exploit for CVE-2023-5217 exists in the wild.
Description
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
References
- https://www.cve.org/CVERecord?id=CVE-2023-5217
- https://nvd.nist.gov/vuln/detail/CVE-2023-5217
OSV
firefox vulnerabilities
osv·2023-10-03·CVSS 6.5
CVE-2023-5169 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-5169,
CVE-2023-5170, CVE-2023-5171, CVE-2023-5172, CVE-2023-5175, CVE-2023-5176)
Ronald Crane discovered that Firefox did not properly manage memory when
non-HTTPS Alternate Services (network.http.altsvc.oe) is enabled. An
attacker could potentially exploit this issue to cause a denial of service.
(CVE-2023-5173)
Clément Lecigne discovered that Firefox did not properly manage memory when
handling VP8 media stream. An attacker-controlled VP8 media stream could
lead to a heap buffer overflow in t
OSV
thunderbird vulnerabilities
osv·2023-10-03·CVSS 8.8
CVE-2023-4057 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2023-4057, CVE-2023-4577,
CVE-2023-4578, CVE-2023-4583, CVE-2023-4585, CVE-2023-5169, CVE-2023-5171,
CVE-2023-5176)
Andrew McCreight discovered that Thunderbird did not properly manage during
the worker lifecycle. An attacker could potentially exploit this issue to
cause a denial of service. (CVE-2023-3600)
Harveer Singh discovered that Thunderbird did not store push notifications
in private browsing mode in encrypted form. An attacker
GHSA
Electron affected by libvpx's heap buffer overflow in vp8 encoding
ghsa·2023-09-28
CVE-2023-5217 [HIGH] CWE-787 Electron affected by libvpx's heap buffer overflow in vp8 encoding
Electron affected by libvpx's heap buffer overflow in vp8 encoding
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
OSV
CVE-2023-5217: Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117
osv·2023-09-28·CVSS 8.8
CVE-2023-5217 [HIGH] CVE-2023-5217: Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
OSV
Electron affected by libvpx's heap buffer overflow in vp8 encoding
osv·2023-09-28
CVE-2023-5217 [HIGH] Electron affected by libvpx's heap buffer overflow in vp8 encoding
Electron affected by libvpx's heap buffer overflow in vp8 encoding
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
GHSA
CefSharp affected by heap buffer overflow in WebP
ghsa·2023-09-21·CVSS 8.8
CVE-2023-4863 [HIGH] CefSharp affected by heap buffer overflow in WebP
CefSharp affected by heap buffer overflow in WebP
**Google is aware that an exploit for [CVE-2023-4863](https://www.cve.org/CVERecord?id=CVE-2023-4863) exists in the wild.**
### Description
Heap buffer overflow in WebP in Google Chrome prior to 116.0.5845.187 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
### References
- https://www.cve.org/CVERecord?id=CVE-2023-4863
- https://nvd.nist.gov/vuln/detail/CVE-2023-4863
- https://www.techtarget.com/searchsecurity/news/366551978/Browser-companies-patch-critical-zero-day-vulnerability
---
**Updated**
There is another related security vulnerability.
> There's another related CVE ([CVE-2023-5217](https://nvd.nist.gov/vuln/detail/CVE-2023-5217)) that is fixe
OSV
CefSharp affected by heap buffer overflow in WebP
osv·2023-09-21·CVSS 8.8
CVE-2023-4863 [HIGH] CefSharp affected by heap buffer overflow in WebP
CefSharp affected by heap buffer overflow in WebP
**Google is aware that an exploit for [CVE-2023-4863](https://www.cve.org/CVERecord?id=CVE-2023-4863) exists in the wild.**
### Description
Heap buffer overflow in WebP in Google Chrome prior to 116.0.5845.187 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
### References
- https://www.cve.org/CVERecord?id=CVE-2023-4863
- https://nvd.nist.gov/vuln/detail/CVE-2023-4863
- https://www.techtarget.com/searchsecurity/news/366551978/Browser-companies-patch-critical-zero-day-vulnerability
---
**Updated**
There is another related security vulnerability.
> There's another related CVE ([CVE-2023-5217](https://nvd.nist.gov/vuln/detail/CVE-2023-5217)) that is fixe
VulnCheck
Google Chromium libvpx Heap Buffer Overflow Vulnerability
vulncheck·2023·CVSS 8.8
CVE-2023-5217 [HIGH] CWE-787 Google Chromium libvpx Heap Buffer Overflow Vulnerability
Google Chromium libvpx Heap Buffer Overflow Vulnerability
Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome.
Affected: Google Chromium libvpx
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2023-Sep; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://ti.qianxin.com/uploads/2024/02/02/
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
blogs_bleepingcomputer·2025-03-11·CVSS 7.8
CVE-2025-24201 [HIGH] Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
## Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
## Sergiu Gatlan
Apple said attackers can exploit the CVE-2025-24201 vulnerability using maliciously crafted web content to break out of the Web Content sandbox.
The company has fixed this out-of-bounds write issue with improved checks to prevent unauthorized actions in iOS 18.3.2, iPadOS 18.3.2 , macOS Sequoia 15.3.2 , visionOS 2.3.2 , and Safari 18.3.1 .
The list of devices impacted by this zero-day is quite extensive, as the bug affects older and newer models, including:
iPhone XS and later,
iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
Macs
Bleepingcomputer
Apple fixes zero-day exploited in 'extremely sophisticated' attacks
blogs_bleepingcomputer·2025-02-10·CVSS 7.8
[HIGH] Apple fixes zero-day exploited in 'extremely sophisticated' attacks
## Apple fixes zero-day exploited in 'extremely sophisticated' attacks
## Sergiu Gatlan
USB Restricted Mode is a security feature ( introduced almost seven years ago in iOS 11.4.1) that blocks USB accessories from creating a data connection if the device has been locked for over an hour. This feature is designed to block forensic software like Graykey and Cellebrite (commonly used by law enforcement) from extracting data from locked iOS devices.
In November, Apple introduced another security feature (dubbed "inactivity reboot") that automatically restarts iPhones after long idle times to re-encrypt data and make it harder to extract by forensic software.
The zero-day vulnerability (tracked as CVE-2025-24200 and reported by Citizen Lab's Bill Marczak) patched today by Apple is an author
Bleepingcomputer
Apple fixes this year’s first actively exploited zero-day bug
blogs_bleepingcomputer·2025-01-27·CVSS 6.5
CVE-2024-23222 [MEDIUM] Apple fixes this year’s first actively exploited zero-day bug
## Apple fixes this year’s first actively exploited zero-day bug
## Sergiu Gatlan
According to the company's official documentation , Core Media "defines the media pipeline used by AVFoundation and other high-level media frameworks found on Apple platforms."
Apple has fixed CVE-2024-23222 with improved memory management in iOS 18.3, iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, visionOS 2.3, and tvOS 18.3.
The list of devices impacted by this zero-day is quite extensive, as the bug affects older and newer models, including:
iPhone XS and later,
iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
macOS Sequoia
Apple Watch Ser
Bleepingcomputer
Apple fixes two zero-days used in attacks on Intel-based Macs
blogs_bleepingcomputer·2024-11-19·CVSS 8.8
CVE-2024-44308 [HIGH] Apple fixes two zero-days used in attacks on Intel-based Macs
## Apple fixes two zero-days used in attacks on Intel-based Macs
## Lawrence Abrams
The JavaScriptCore CVE-2024-44308 flaw allows attackers to achieve remote code execution through maliciously crafted web content. The other flaw, CVE-2024-44309, allows cross-site scripting (CSS) attacks.
The company says it addressed the security flaws in macOS Sequoia 15.1.1 .
As the same components are found in other Apple operating systems, it was also fixed in iOS 17.7.2 and iPadOS 17.7.2 , iOS 18.1.1 and iPadOS 18.1.1 , and visionOS 2.1.1 .
While Apple says both flaws were discovered by Clément Lecigne and Benoît Sevens of Google's Threat Analysis Group, the company has not provided further details on how they were exploited.
BleepingComputer contacted Google to learn how the flaws were exploite
Bleepingcomputer
Apple fixes first zero-day bug exploited in attacks this year
blogs_bleepingcomputer·2024-01-22·CVSS 8.8
[HIGH] Apple fixes first zero-day bug exploited in attacks this year
## Apple fixes first zero-day bug exploited in attacks this year
## Sergiu Gatlan
"Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited," Apple said today.
The company has yet to attribute the discovery of this security vulnerability to a security researcher. Although the company disclosed that it's aware of in-the-wild exploitation, it has yet to publish further details regarding these attacks.
Apple addressed CVE-2024-23222 with improved checks in iOS 16.7.5 and later, iPadOS 16.7.5 and later, and macOS Monterey 12.7.3 and higher, as well as on tvOS 17.3 and later.
The complete list of devices impacted by this WebKit zero-day is quite extensive, as the bug affects older and newer models, i
Wiz
Crying out Cloud – Our Favorite Stories of 2023 | Wiz Blog
blogs_wiz·2024-01-16·CVSS 7.8
[HIGH] Crying out Cloud – Our Favorite Stories of 2023 | Wiz Blog
2023 certainly had its share of tumultuous events that shaped the perceptions of cloud customers everywhere — there were supply chain attacks, critical 0day vulnerabilities and advancements in both AI and AI security that all left their mark on how we approach cloud security. As the year came to a close, the Crying out Cloud team (Eden, Merav and Amitai) sat down to discuss what we felt were our most interesting podcast episodes and newsletter editions of 2023.
# High Profile Vulnerabilities
## Merav’s picks
### Chrome vulnerabilities that weren’t actually Chrome vulnerabilities
(from our newsletter)
Several critical vulnerabilities in Google Chrome were published in 2023. In a few cases, items that fell into the Chrome category were hiding much more interesting vulnerabilities. CVE-2
Bleepingcomputer
Google fixes first actively exploited Chrome zero-day of 2024
blogs_bleepingcomputer·2024-01-16·CVSS 8.8
CVE-2024-0519 [HIGH] Google fixes first actively exploited Chrome zero-day of 2024
## Google fixes first actively exploited Chrome zero-day of 2024
## Sergiu Gatlan
Although Google says the security update could take days or weeks to reach all impacted users, it was available immediately when BleepingComputer checked for updates today.
Those who prefer not to update their web browser manually can rely on Chrome to automatically check for new updates and install them after the next launch.
The high-severity zero-day vulnerability ( CVE-2024-0519 ) is due to a high-severity out-of-bounds memory access weakness in the Chrome V8 JavaScript engine, which remote attackers can exploit via a crafted HTML page to gain access to data beyond the memory buffer through heap corruption, providing them access to sensitive information or triggering a crash.
"The expected sentinel
Wiz
Crying out Cloud – Our Favorite Stories of 2023 | Wiz Blog
blogs_wiz·2024-01-16·CVSS 7.8
[HIGH] Crying out Cloud – Our Favorite Stories of 2023 | Wiz Blog
2023 certainly had its share of tumultuous events that shaped the perceptions of cloud customers everywhere — there were supply chain attacks, critical 0day vulnerabilities and advancements in both AI and AI security that all left their mark on how we approach cloud security. As the year came to a close, the Crying out Cloud team ( Eden , Merav and Amitai ) sat down to discuss what we felt were our most interesting podcast episodes and newsletter editions of 2023.
## High Profile Vulnerabilities
## Merav’s picks
## Chrome vulnerabilities that weren’t actually Chrome vulnerabilities
(from our newsletter )
Several critical vulnerabilities in Google Chrome were published in 2023. In a few cases, items that fell into the Chrome category were hiding much more interesting vulnerabilities .
Bleepingcomputer
Google fixes 8th Chrome zero-day exploited in attacks this year
blogs_bleepingcomputer·2023-12-20·CVSS 8.8
[HIGH] Google fixes 8th Chrome zero-day exploited in attacks this year
## Google fixes 8th Chrome zero-day exploited in attacks this year
## Sergiu Gatlan
The bug was discovered and reported by Clément Lecigne and Vlad Stolyarov of Google's Threat Analysis Group (TAG), a collective of security experts whose primary goal is to defend Google customers from state-sponsored attacks.
Google's Threat Analysis Group (TAG) frequently discovers zero-day bugs exploited by government-sponsored threat actors in targeted attacks aiming to deploy spyware on the devices of high-risk individuals, including opposition politicians, dissidents, and journalists.
Even though the security update could take days or weeks to reach all users, according to Google, it was available immediately when BleepingComputer checked for updates earlier today.
Individuals who prefer not t
Bleepingcomputer
Apple emergency updates fix recent zero-days on older iPhones
blogs_bleepingcomputer·2023-12-11·CVSS 6.5
[MEDIUM] Apple emergency updates fix recent zero-days on older iPhones
## Apple emergency updates fix recent zero-days on older iPhones
## Sergiu Gatlan
They can let attackers obtain access to sensitive data through and execute arbitrary code using maliciously crafted webpages designed to exploit out-of-bounds and memory corruption bugs on unpatched devices.
Today, Apple addressed the zero-days in iOS 16.7.3, iPadOS 16.7.3 , tvOS 17.2 , and watchOS 10.2 with improved input validation and locking.
The company says the bugs are now also patched on the following list of devices:
iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Apple TV HD and Apple TV 4K (all models)
Apple Watch Series 4 and later
Clément Lecigne, a security researcher from Google's Threat
Securelist
PC malware statistics, Q3 2023
blogs_securelist·2023-12-01
PC malware statistics, Q3 2023
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used in cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks on IoT honeypots
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q3 2023
- IT threat evolution in Q3 2023. Non-mobile statistics
- IT threat evolution in Q3 2023. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q3 2023:
- Kaspersky solutions blocked 694,400,301 attacks from online resources across the globe.
- A total of 169,194,807 unique links were recognized as malicious by Web Anti-Virus
Securelist
IT threat evolution in Q3 2023. Non-mobile statistics
blogs_securelist·2023-12-01
IT threat evolution in Q3 2023. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Geography of financial malware attacks
Ransomware programs
Quarterly trends and highlights
Vulnerability exploitation
More attacks on healthcare
Most prolific groups
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used in cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks on IoT honeypots
Attacks via web resources
Countries and territories that serve as sourc
Bleepingcomputer
Google Chrome emergency update fixes 7th zero-day exploited in 2023
blogs_bleepingcomputer·2023-11-28·CVSS 9.6
[CRITICAL] Google Chrome emergency update fixes 7th zero-day exploited in 2023
## Google Chrome emergency update fixes 7th zero-day exploited in 2023
## Sergiu Gatlan
The vulnerability has been addressed in the Stable Desktop channel, with patched versions rolling out globally to Windows users (119.0.6045.199/.200) and Mac and Linux users (119.0.6045.199).
Although the advisory notes that the security update may take days or weeks to reach the entire user base, it was available immediately when BleepingComputer checked for updates earlier today.
Users who don't want to update manually can rely on the web browser to check for new updates automatically and install them after the next launch.
## Likely exploited in spyware attacks
This high-severity zero-day vulnerability stems from an integer overflow weakness within the Skia open-source 2D graphics library, pos
Wiz
Crying Out Cloud - November Newsletter | Wiz
blogs_wiz·2023-11-01·CVSS 9.8
CVE-2023-42115 [CRITICAL] Crying Out Cloud - November Newsletter | Wiz
The past month has brought a series of vulnerabilities and security incidents that have left users affected. Amidst the noise, we've taken it upon ourselves to curate the most significant developments for you.
Here are our top picks of cloud security highlights!
## 🐞 High Profile Vulnerabilities
## Critical and high severity 0day vulnerabilities in Exim
Multiple vulnerabilities were disclosed in Exim Mail Transfer Agent (MTA), including CVE-2023-42115, which is a critical vulnerability enabling unauthenticated attackers to remotely execute code on publicly exposed Exim servers with a specific non-default configuration. This issue results from improper input validation that leads to writing arbitrary code past the end of the buffer.
According to Wiz data, although Exim is very prevalen
Bleepingcomputer
Apple fixes iOS Kernel zero-day vulnerability on older iPhones
blogs_bleepingcomputer·2023-10-12·CVSS 7.8
CVE-2023-5217 [HIGH] Apple fixes iOS Kernel zero-day vulnerability on older iPhones
## Apple fixes iOS Kernel zero-day vulnerability on older iPhones
## Sergiu Gatlan
Apple has now also fixed the issue in iOS 16.7.1 and iPadOS 16.7.1 with improved checks, but it has yet to reveal who discovered and reported the flaw.
The second one, a bug identified as CVE-2023-5217, is caused by a heap buffer overflow vulnerability within the VP8 encoding of the open-source libvpx video codec library. This flaw could let threat actors gain arbitrary code execution upon successful exploitation.
Even though Apple did not confirm any instances of exploitation in the wild, Google previously patched the libvpx bug as a zero-day in its Chrome web browser. Microsoft also addressed the same vulnerability in its Edge, Teams, and Skype products.
Google attributed the discovery of CVE-2023-521
Krebs
Patch Tuesday, October 2023 Edition
blogs_krebs·2023-10-10·CVSS 4.4
CVE-2023-42724 [MEDIUM] Patch Tuesday, October 2023 Edition
Microsoft today issued security updates for more than 100 newly-discovered vulnerabilities in its Windows operating system and related software, including four flaws that are already being exploited. In addition, Apple recently released emergency updates to quash a pair of zero-day bugs in iOS.
Apple last week shipped emergency updates in iOS 17.0.3 and iPadOS 17.0.3 in response to active attacks. The patch fixes CVE-2023-42724, which attackers have been using in targeted attacks to elevate their access on a local device.
Apple said it also patched CVE-2023-5217, which is not listed as a zero-day bug. However, as Bleeping Computer pointed out, this flaw is caused by a weakness in the open-source “libvpx” video codec library, which was previously patched as a zero-day flaw by Google in th
Krebs
Patch Tuesday, October 2023 Edition
blogs_krebs·2023-10-10·CVSS 4.4
CVE-2023-42724 [MEDIUM] Patch Tuesday, October 2023 Edition
Microsoft today issued security updates for more than 100 newly-discovered vulnerabilities in its Windows operating system and related software, including four flaws that are already being exploited. In addition, Apple recently released emergency updates to quash a pair of zero-day bugs in iOS .
Apple last week shipped emergency updates in iOS 17.0.3 and iPadOS 17.0.3 in response to active attacks. The patch fixes CVE-2023-42724 , which attackers have been using in targeted attacks to elevate their access on a local device.
Apple said it also patched CVE-2023-5217 , which is not listed as a zero-day bug. However, as Bleeping Computer pointed out , this flaw is caused by a weakness in the open-source “ libvpx ” video codec library, which was previously patched as a zero-day flaw by Google
Checkpoint
9th October – Threat Intelligence Report
blogs_checkpoint·2023-10-09
CVE-2023-4863 9th October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 9th October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 9th October, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The American Rock County Public Health Department, which serves more than 160K people across Wisconsin area, has been a victim of a ransomware attack that forced officials to take some systems offline. Cuba ransomware gang has claimed responsibility for the attack, claiming to have stolen financial documents, tax informatio
Wiz
Crying Out Cloud - September Newsletter | Wiz
blogs_wiz·2023-10-05·CVSS 8.2
[HIGH] Crying Out Cloud - September Newsletter | Wiz
Welcome back! Over the last busy month, we’ve seen many critical vulnerabilities pop up and there have been reports of several impactful security incidents. We’ve sifted through the noise to bring you the real game-changers.
Here are our top picks of cloud security highlights!
## ✨ Highlights
## Misconfigured SAS token leads to data leak
Wiz Research discovered that Microsoft accidentally exposed 38TB of sensitive data through a misconfigured SAS token published in a public GitHub repository in the course of sharing AI data with the community. This data included secrets, private keys, passwords, and over 30,000 internal Microsoft Teams messages. Read our blogpost for guidance on secure usage of SAS tokens.
Learn more in our blog .
## 🐞 High Profile Vulnerabilities
## Critical vulner
Bleepingcomputer
Apple emergency update fixes new zero-day used to hack iPhones
blogs_bleepingcomputer·2023-10-04·CVSS 7.8
[HIGH] Apple emergency update fixes new zero-day used to hack iPhones
## Apple emergency update fixes new zero-day used to hack iPhones
## Sergiu Gatlan
While Apple said it addressed the security issue in iOS 17.0.3 and iPadOS 17.0.3 with improved checks, it has yet to reveal who found and reported the flaw.
The list of impacted devices is quite extensive, and it includes:
iPhone XS and later
iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
Apple also addressed a bug tracked as CVE-2023-5217 and caused by a heap buffer overflow weakness in the VP8 encoding of the open-source libvpx video codec library, which could allow arbitrary code execution following successful exploitation.
While Apple
Sentinelone
Beyond the WebP Flaw | An In-depth Look at 2023's Browser Security Challenges
blogs_sentinelone·2023-10-03
Beyond the WebP Flaw | An In-depth Look at 2023's Browser Security Challenges
This week, Firefox users were urged to apply Mozilla’s latest updates against a critical flaw that could allow attackers to take control of affected systems. It follows hard on the heels of similar updates for Microsoft Edge, Google Chrome, and Apple’s Safari browser. All have been heavily impacted by an actively exploited vulnerability in the WebP code library.
Although the WebP vulnerability affects other software as well, browsers are by far and away the most ubiquitous and widely used applications on end user devices . Having a foothold in a compromised browser gives threat actors access to sensitive information and potential avenues into targeted environments.
In this post, we take a deep dive into browser security , exploring the differences between vulnerabilities and exploits, ze
Sentinelone
Beyond the WebP Flaw | An In-depth Look at 2023's Browser Security Challenges
blogs_sentinelone·2023-10-03
Beyond the WebP Flaw | An In-depth Look at 2023's Browser Security Challenges
This week, Firefox users were urged to apply Mozilla’s latest updates against a critical flaw that could allow attackers to take control of affected systems. It follows hard on the heels of similar updates for Microsoft Edge, Google Chrome, and Apple’s Safari browser. All have been heavily impacted by an actively exploited vulnerability in the WebP code library.
Although the WebP vulnerability affects other software as well, browsers are by far and away the most ubiquitous and widely used applications on end user devices. Having a foothold in a compromised browser gives threat actors access to sensitive information and potential avenues into targeted environments.
In this post, we take a deep dive into browser security, exploring the differences between vulnerabilities and exploits, zero
Bleepingcomputer
Microsoft Edge, Teams get fixes for zero-days in open-source libraries
blogs_bleepingcomputer·2023-10-03·CVSS 8.8
[HIGH] Microsoft Edge, Teams get fixes for zero-days in open-source libraries
## Microsoft Edge, Teams get fixes for zero-days in open-source libraries
## Sergiu Gatlan
The libwebp library is used by a large number of projects for encoding and decoding images in the WebP format, including modern web browsers like Safari, Mozilla Firefox , Microsoft Edge, Opera, and the native Android web browsers, as well as popular apps like 1Password and Signal .
libvpx is used for VP8 and VP9 video encoding and decoding by desktop video player software and online streaming services like Netflix, YouTube, and Amazon Prime Video.
"Microsoft is aware and has released patches associated with the two Open-Source Software security vulnerabilities, CVE-2023-4863 and CVE-2023-5217," Redmond revealed in a Microsoft Security Response Center advisory published Monday.
The two security
Checkpoint
2nd October – Threat Intelligence Report
blogs_checkpoint·2023-10-02
CVE-2023-5217 2nd October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 2nd October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 2nd October, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Check Point researchers have detected a phishing campaign exploiting popular file-sharing program Dropbox. The threat actors use legitimate Dropbox pages to send official email messages to the victims, which will then redirect the recipients to credential stealing pages.
Japanese entertainment giant Sony, as well as major
Wiz
CVE-2023-4863 and CVE-2023-5217 Exploited in the Wild | Wiz Blog
blogs_wiz·2023-10-01·CVSS 7.8
CVE-2023-4863 [HIGH] CVE-2023-4863 and CVE-2023-5217 Exploited in the Wild | Wiz Blog
CVE-2023-4863 is a critical vulnerability in libwebp, and CVE-2023-5217 is a high severity vulnerability in libvpx, both reportedly exploited in the wild. Both are mainly client side vulnerabilities and thus unlikely to be exploitable on most affected cloud workloads other than virtual desktops and servers that handle images or video. Customers should therefore prioritize patching these cases as well as vulnerable instances detected in build environments.
## What is CVE-2023-4863?
## Background
On September 11th, 2023, a vulnerability was assigned CVE-2023-4863 that reportedly only affected Chrome. More specifically, it was described as a heap buffer overflow in WebP in Chrome, allowing a remote attacker to perform an out of bounds memory write via a crafted HTML page.
However, further
Wiz
CVE-2023-4863 and CVE-2023-5217 Exploited in the Wild | Wiz Blog
blogs_wiz·2023-10-01·CVSS 7.8
CVE-2023-4863 [HIGH] CVE-2023-4863 and CVE-2023-5217 Exploited in the Wild | Wiz Blog
CVE-2023-4863 is a critical vulnerability in libwebp, and CVE-2023-5217 is a high severity vulnerability in libvpx, both reportedly exploited in the wild. Both are mainly client side vulnerabilities and thus unlikely to be exploitable on most affected cloud workloads other than virtual desktops and servers that handle images or video. Customers should therefore prioritize patching these cases as well as vulnerable instances detected in build environments.
# What is CVE-2023-4863?
## Background
On September 11th, 2023, a vulnerability was assigned CVE-2023-4863 that reportedly only affected Chrome. More specifically, it was described as a heap buffer overflow in WebP in Chrome, allowing a remote attacker to perform an out of bounds memory write via a crafted HTML page.
However, further
Bleepingcomputer
Google fixes fifth actively exploited Chrome zero-day of 2023
blogs_bleepingcomputer·2023-09-27·CVSS 8.8
CVE-2023-5217 [HIGH] Google fixes fifth actively exploited Chrome zero-day of 2023
## Google fixes fifth actively exploited Chrome zero-day of 2023
## Sergiu Gatlan
While the advisory says it will likely take days or weeks until the patched version reaches the entire user base, the update was immediately available when BleepingComputer checked for updates.
The web browser will also auto-check for new updates and automatically install them after the next launch.
## Exploited in spyware attacks
The high-severity zero-day vulnerability ( CVE-2023-5217 ) is caused by a heap buffer overflow weakness in the VP8 encoding of the open-source libvpx video codec library, a flaw whose impact ranges from app crashes to arbitrary code execution.
The bug was reported by Google Threat Analysis Group (TAG) security researcher Clément Lecigne on Monday, September 25.
Google TAG res
arXiv
TikTag: Breaking ARM's Memory Tagging Extension with Speculative Execution
arxiv_fulltext·2024-06-13
TikTag: Breaking ARM's Memory Tagging Extension with Speculative Execution
: Breaking ARM's Memory Tagging Extension with Speculative Execution
fancyplain
Rev.
\ of LastPage
Juhee Kim
Seoul National University
[email protected]
Jinbum Park
Samsung Research
[email protected]
Sihyeon Roh
Seoul National University
[email protected]
Jaeyoung Chung
Seoul National University
[email protected]
Youngjoo Lee
Seoul National University
[email protected]
Taesoo Kim
Samsung Research and
Georgia Institute of Technology
[email protected]
Byoungyoung Lee
Seoul National University
[email protected]
## Abstract
ARM Memory Tagging Extension (MTE) is a new hardware feature
introduced in ARMv8.5-A architecture, aiming to detect memory
corruption vulnerabilities.
The low overhead of MTE makes it an attractive solution to mitigate
memory corruptio
arXiv
Unveiling Hidden Links Between Unseen Security Entities
arxiv_fulltext·2024-03-04
Unveiling Hidden Links Between Unseen Security Entities
VulnScopper
Unveiling Hidden Links Between Unseen Security Entities
Daniel Alfasi
Reichman University, Israel
Tal Shapira
The Hebrew University of Jerusalem, Israel
Anat Bremler Barr
Tel Aviv University, Israel
empty
### Abstract
The proliferation of software vulnerabilities poses a significant challenge for security databases and analysts tasked with their timely identification, classification, and remediation. With the National Vulnerability Database (NVD) reporting an ever-increasing number of vulnerabilities, the traditional manual analysis becomes untenably time-consuming and prone to errors. This paper introduces , an innovative approach that utilizes multi-modal representation learning, combining Knowledge Graphs (KG) and Natural Language Processing (NLP), to automate and
Bugzilla
Chrome libvpx 0day
bugzilla·2023-09-27·CVSS 8.8
[HIGH] Chrome libvpx 0day
Chrome libvpx 0day
Chrome is affected by a 0day bug exploiting a vulnerability in libvpx, which is exposed through the WebCodec API.
We do not support the API but use libvpx elsewhere (mostly WebRTC) and should therefore investigate if this affects us and how fast we want to ship an update.
I'm rating this sec-critical, in case it is a Firefox 0day. Naturally, we want to rank this down if it isn't.
Discussion:
Created attachment 9355415
asan stacktrace from Chrome unit test
---
Created attachment 9355416
gtest diff
---
libvpx patch: https://chromium.googlesource.com/webm/libvpx/+/3fbd1dca6a4d2dad332a2110d646e4ffef36d590%5E%21/
webcodec patch (for comparison, not relevant to us):
https://chromium.googlesource.com/chromium/src/+/dd8d9efe3251e33dfe19fa0163626aa1b35946d0
---
We are
http://seclists.org/fulldisclosure/2023/Oct/12http://seclists.org/fulldisclosure/2023/Oct/16http://www.openwall.com/lists/oss-security/2023/09/28/5http://www.openwall.com/lists/oss-security/2023/09/28/6http://www.openwall.com/lists/oss-security/2023/09/29/1http://www.openwall.com/lists/oss-security/2023/09/29/11http://www.openwall.com/lists/oss-security/2023/09/29/12http://www.openwall.com/lists/oss-security/2023/09/29/14http://www.openwall.com/lists/oss-security/2023/09/29/2http://www.openwall.com/lists/oss-security/2023/09/29/7http://www.openwall.com/lists/oss-security/2023/09/29/9http://www.openwall.com/lists/oss-security/2023/09/30/1http://www.openwall.com/lists/oss-security/2023/09/30/2http://www.openwall.com/lists/oss-security/2023/09/30/3http://www.openwall.com/lists/oss-security/2023/09/30/4http://www.openwall.com/lists/oss-security/2023/09/30/5http://www.openwall.com/lists/oss-security/2023/10/01/1http://www.openwall.com/lists/oss-security/2023/10/01/2http://www.openwall.com/lists/oss-security/2023/10/01/5http://www.openwall.com/lists/oss-security/2023/10/02/6http://www.openwall.com/lists/oss-security/2023/10/03/11https://arstechnica.com/security/2023/09/new-0-day-in-chrome-and-firefox-is-likely-to-plague-other-software/https://bugzilla.redhat.com/show_bug.cgi?id=2241191https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.htmlhttps://crbug.com/1486441https://github.com/webmproject/libvpx/commit/3fbd1dca6a4d2dad332a2110d646e4ffef36d590https://github.com/webmproject/libvpx/commit/af6dedd715f4307669366944cca6e0417b290282https://github.com/webmproject/libvpx/releases/tag/v1.13.1https://github.com/webmproject/libvpx/tagshttps://lists.debian.org/debian-lts-announce/2023/09/msg00038.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00001.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/4MFWDFJSSIFKWKNOCTQCFUNZWAXUCSS4/https://lists.fedoraproject.org/archives/list/[email protected]/message/55YVCZNAVY3Y5E4DWPWMX2SPKZ2E5SOV/https://lists.fedoraproject.org/archives/list/[email protected]/message/AY642Z6JZODQJE7Z62CFREVUHEGCXGPD/https://lists.fedoraproject.org/archives/list/[email protected]/message/BCVSHVX2RFBU3RMCUFSATVQEJUFD4Q63/https://lists.fedoraproject.org/archives/list/[email protected]/message/CWEJYS5NC7KVFYU3OAMPKQDYN6JQGVK6/https://lists.fedoraproject.org/archives/list/[email protected]/message/TE7F54W5O5RS4ZMAAC7YK3CZWQXIDSKB/https://lists.fedoraproject.org/archives/list/[email protected]/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I/https://pastebin.com/TdkC4pDvhttps://security-tracker.debian.org/tracker/CVE-2023-5217https://security.gentoo.org/glsa/202310-04https://security.gentoo.org/glsa/202401-34https://stackdiary.com/google-discloses-a-webm-vp8-bug-tracked-as-cve-2023-5217/https://support.apple.com/kb/HT213961https://support.apple.com/kb/HT213972https://twitter.com/maddiestone/status/1707163313711497266https://www.debian.org/security/2023/dsa-5508https://www.debian.org/security/2023/dsa-5509https://www.debian.org/security/2023/dsa-5510https://www.mozilla.org/en-US/security/advisories/mfsa2023-44/https://www.openwall.com/lists/oss-security/2023/09/28/5http://seclists.org/fulldisclosure/2023/Oct/12http://seclists.org/fulldisclosure/2023/Oct/16http://www.openwall.com/lists/oss-security/2023/09/28/5http://www.openwall.com/lists/oss-security/2023/09/28/6http://www.openwall.com/lists/oss-security/2023/09/29/1http://www.openwall.com/lists/oss-security/2023/09/29/11http://www.openwall.com/lists/oss-security/2023/09/29/12http://www.openwall.com/lists/oss-security/2023/09/29/14http://www.openwall.com/lists/oss-security/2023/09/29/2http://www.openwall.com/lists/oss-security/2023/09/29/7http://www.openwall.com/lists/oss-security/2023/09/29/9http://www.openwall.com/lists/oss-security/2023/09/30/1http://www.openwall.com/lists/oss-security/2023/09/30/2http://www.openwall.com/lists/oss-security/2023/09/30/3http://www.openwall.com/lists/oss-security/2023/09/30/4http://www.openwall.com/lists/oss-security/2023/09/30/5http://www.openwall.com/lists/oss-security/2023/10/01/1http://www.openwall.com/lists/oss-security/2023/10/01/2http://www.openwall.com/lists/oss-security/2023/10/01/5http://www.openwall.com/lists/oss-security/2023/10/02/6http://www.openwall.com/lists/oss-security/2023/10/03/11https://arstechnica.com/security/2023/09/new-0-day-in-chrome-and-firefox-is-likely-to-plague-other-software/https://bugzilla.redhat.com/show_bug.cgi?id=2241191https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.htmlhttps://crbug.com/1486441https://github.com/webmproject/libvpx/commit/3fbd1dca6a4d2dad332a2110d646e4ffef36d590https://github.com/webmproject/libvpx/commit/af6dedd715f4307669366944cca6e0417b290282https://github.com/webmproject/libvpx/releases/tag/v1.13.1https://github.com/webmproject/libvpx/tagshttps://lists.debian.org/debian-lts-announce/2023/09/msg00038.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00001.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/4MFWDFJSSIFKWKNOCTQCFUNZWAXUCSS4/https://lists.fedoraproject.org/archives/list/[email protected]/message/55YVCZNAVY3Y5E4DWPWMX2SPKZ2E5SOV/https://lists.fedoraproject.org/archives/list/[email protected]/message/AY642Z6JZODQJE7Z62CFREVUHEGCXGPD/https://lists.fedoraproject.org/archives/list/[email protected]/message/BCVSHVX2RFBU3RMCUFSATVQEJUFD4Q63/https://lists.fedoraproject.org/archives/list/[email protected]/message/CWEJYS5NC7KVFYU3OAMPKQDYN6JQGVK6/https://lists.fedoraproject.org/archives/list/[email protected]/message/TE7F54W5O5RS4ZMAAC7YK3CZWQXIDSKB/https://lists.fedoraproject.org/archives/list/[email protected]/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I/https://pastebin.com/TdkC4pDvhttps://security-tracker.debian.org/tracker/CVE-2023-5217https://security.gentoo.org/glsa/202310-04https://security.gentoo.org/glsa/202401-34https://stackdiary.com/google-discloses-a-webm-vp8-bug-tracked-as-cve-2023-5217/https://support.apple.com/kb/HT213961https://support.apple.com/kb/HT213972https://twitter.com/maddiestone/status/1707163313711497266https://www.debian.org/security/2023/dsa-5508
+ 5 more references
2023-09-28
Published
2023-10-02
Added to CISA KEV
Exploited in the wild