CVE-2023-7024: Heap buffer overflow in WebRTC
Chromium: CVE-2023-7024 Heap buffer overflow in WebRTC
Other sources
Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using WebRTC, including but not limited to Google Chrome.
— CISA
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2023-7024 exists in the wild.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.129-1~deb11u1Fixed in 120.0.6099.129-1~deb12u1Fixed in 120.0.6099.129-1 - Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 120.0.6099.129 - Upgrade
Upgrade
Chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.129 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.129-1~deb11u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.129-1~deb12u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.129-1 - Compensating control
For Microsoft Edge, Microsoft Edge Beta, and other browsers using WebRTC where a vendor patch is not yet available, apply vendor-provided mitigations; if mitigations are unavailable, discontinue use of the product.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-7024?
CVE-2023-7024 has been classified as a moderate severity vulnerability.
How do I fix CVE-2023-7024?
To fix CVE-2023-7024, ensure that you update Google Chrome, Chromium, or Microsoft Edge to the latest version.
Which products are affected by CVE-2023-7024?
CVE-2023-7024 affects specific versions of Google Chrome, Chromium, and Microsoft Edge (Chromium-based).
When was CVE-2023-7024 disclosed?
CVE-2023-7024 was disclosed in early January 2024.
What platforms are vulnerable to CVE-2023-7024?
CVE-2023-7024 affects multiple platforms including Debian and Fedora Linux distributions.