A new buffer overflow vulnerability, identified as CVE-2023-5217, has been discovered in Google Chrome. This issue arises from the incorporation of a video compression format into a software library utilized by Chrome. It allows attackers to execute remote code on a target system by manipulating heap memory through a malicious HTML page. This vulnerability affects Google Chrome versions earlier than 117.0.5938.132 and libvpx library versions before 1.13.1. https://www.darkreading.com/vulnerabilities-threats/chrome-flags-third-zero-day-this-month-tied-to-spying-exploits

Reply to this note

Please Login to reply.

Discussion

No replies yet.