CVE-2023-7024
HIGH KEVGoogle Chrome < 120.0.6099.129 - Out-of-Bounds Write
Title source: ruleDescription
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Exploits (2)
References (7)
Scores
CVSS v3
8.8
EPSS
0.0287
EPSS Percentile
86.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CISA KEV
2024-01-02
VulnCheck KEV
2023-12-19
InTheWild.io
2023-12-19
ENISA EUVD
EUVD-2023-59215
CWE
CWE-787
Status
published
Products (5)
debian/debian_linux
11.0
debian/debian_linux
12.0
fedoraproject/fedora
38
fedoraproject/fedora
39
google/chrome
< 120.0.6099.129
Published
Dec 21, 2023
KEV Added
Jan 02, 2024
Tracked Since
Feb 18, 2026