Threat intelligence report · CISA KEV

CVE-2023-5217: Google Chromium libvpx Heap Buffer Overflow Vulnerability

Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

· high severity · unattributed attribution

Evidence and provenance

Original source
CISA KEV report ↗
Published
2023-10-02T00:00:00Z
Confidence basis
No actor match
Record ID
709e70fbf138f3816dba

Vulnerabilities

CVE-2023-5217

Use and citation

Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.