Skip to content
COOEY

EXPOSURES › CVE-2023-7024

CVE-2023-7024

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-01-02 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-7024 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatchedransomware

Google Chromium WebRTC suffered a heap buffer overflow vulnerability (CVE-2023-7024) actively exploited in the wild via crafted HTML pages.

This heap buffer overflow in Google's WebRTC implementation allows remote attackers to exploit heap corruption through crafted HTML pages, posing a significant risk to DIB organizations relying on WebRTC for secure communications. The vulnerability is actively exploited in the wild, requiring immediate patching to prevent potential remote code execution and data exfiltration.

Shame score — Active exploitation of a heap buffer overflow in a widely-used WebRTC component indicates a failure to maintain timely security patches in a critical communication library.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using WebRTC, including but not limited to Google Chrome.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized