EXPOSURES › CVE-2023-7024
CVE-2023-7024
HIGH ⌖ ON CISA KEV · EXPLOITEDGoogle Chromium WebRTC suffered a heap buffer overflow vulnerability (CVE-2023-7024) actively exploited in the wild via crafted HTML pages.
This heap buffer overflow in Google's WebRTC implementation allows remote attackers to exploit heap corruption through crafted HTML pages, posing a significant risk to DIB organizations relying on WebRTC for secure communications. The vulnerability is actively exploited in the wild, requiring immediate patching to prevent potential remote code execution and data exfiltration.
Shame score — Active exploitation of a heap buffer overflow in a widely-used WebRTC component indicates a failure to maintain timely security patches in a critical communication library.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using WebRTC, including but not limited to Google Chrome.
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |