CISA Known Exploited Vulnerability (KEV)
Google Chromium WebRTC Heap Buffer Overflow Vulnerability
January 2, 2024
January 23, 2024
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
References
- https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html
- https://crbug.com/1513170
- https://lists.fedoraproject.org/archives/list/[email protected]/message/6M6AJDHUL6EDPURWQXGLUFJNDE7SOJT3/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/U6JL4VHZMHFGEGQYTF74533ZNRWMCMMR/
- https://security.gentoo.org/glsa/202401-34
- https://www.debian.org/security/2023/dsa-5585
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-787 |
Out-of-bounds Write |