Google Chromium WebRTC Heap Buffer Overflow Vulnerability
Summary
| CVE | CVE-2023-7024 |
|---|---|
| State | PUBLISHED |
| Assigner | Unknown |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-12-21 23:15:00 UTC |
| Updated | 2024-01-31 17:15:00 UTC |
| Description | Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using WebRTC, including but not limited to Google Chrome. |
Risk And Classification
EPSS: 0.012980000 probability, percentile 0.796620000 (date 2026-04-01)
CISA KEV: Listed on 2024-01-02; due 2024-01-23; ransomware use Unknown
Problem Types: CWE-787
CISA Known Exploited Vulnerability
| Vendor | |
|---|---|
| Product | Chromium WebRTC |
| Name | Google Chromium WebRTC Heap Buffer Overflow Vulnerability |
| Required Action | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
| Notes | This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html; https://nvd.nist.gov/vuln/detail/CVE-2023-7024 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Operating System | Debian | Debian Linux | 12.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 38 | All | All | All |
| Operating System | Fedoraproject | Fedora | 39 | All | All | All |
| Application | Chrome | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| crbug.com/1513170 | crbug.com | ||
| chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html | chromereleases.googleblog.com | ||
| lists.fedoraproject.org/archives/list/[email protected]/messag... | lists.fedoraproject.org | ||
| www.debian.org/security/2023/dsa-5585 | www.debian.org | ||
| Chromium, Google Chrome, Microsoft Edge: Multiple Vulnerabilities (GLSA 202401-34) — Gentoo security | security.gentoo.org | ||
| lists.fedoraproject.org/archives/list/[email protected]/messag... | lists.fedoraproject.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 284826 Fedora Security Update for chromium (FEDORA-2023-ed327967b4)
- 285074 Fedora Security Update for chromium (FEDORA-2023-1de2fe25c4)
- 379169 Google Chrome Prior to 120.0.6099.129 Multiple Vulnerabilities
- 379174 Microsoft Edge Based on Chromium Prior to 120.0.2210.91 Multiple Vulnerabilities
- 510676 Alpine Linux Security Update for qt6-qtwebengine
- 510689 Alpine Linux Security Update for qt5-qtwebengine
- 6000394 Debian Security Update for chromium (DSA 5585-1)
- 691382 Free Berkeley Software Distribution (FreeBSD) Security Update for chromium (1b2a8e8a-9fd5-11ee-86bb-a8a1599412c6)
- 691384 Free Berkeley Software Distribution (FreeBSD) Security Update for electron{26,27} (7015ab21-9230-490f-a2fe-f7557e3de25d)
- 691406 Free Berkeley Software Distribution (FreeBSD) Security Update for qt6 (a25b323a-bed9-11ee-bdd6-4ccc6adda413)
- 691407 Free Berkeley Software Distribution (FreeBSD) Security Update for qt5 (a11e7dd1-bed4-11ee-bdd6-4ccc6adda413)
- 710849 Gentoo Linux Chromium, Google Chrome, Microsoft Edge Multiple Vulnerabilities (GLSA 202401-34)
- 710863 Gentoo Linux QtWebEngine Multiple Vulnerabilities (GLSA 202402-14)
- 755551 OpenSUSE Security Update for opera (openSUSE-SU-2024:0001-1)
- 755552 OpenSUSE Security Update for opera (openSUSE-SU-2024:0002-1)