Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 32.1%; technical severity is CVSS 8.8.
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Who should care
- Teams operating macOS, Couchbase Server, Debian Linux +4 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether macOS, Couchbase Server, Debian Linux +4 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Debian Security advisory Dsa 5420
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- CWE
- CWE-843
- Affected versions
- Apple macOS (Version -); Couchbase Couchbase Server (End Excluding 7.1.5 | Version 7.2.0); Debian Debian Linux (Version 11.0 | Version 12.0); Fedoraproject Fedora (Version 37 | Version 38); Google Chrome (End Excluding 114.0.5735.110); Google Chromium V8; Linux Linux Kernel (Version -)
- Fixed versions
- Couchbase Couchbase Server (Fixed from 7.1.5); Google Chrome (Fixed from 114.0.5735.110)
- Published
- 5 June 2023
- Attack vector
- Network
- Privileges required
- None
- User interaction
- Required
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 32.1%
- Signal calculated at 75
External references
- CISA Government advisory CVE-2023-3079
- Packetstormsecurity Third-party advisory Chrome V8 Type Confusion
- Packetstormsecurity Third-party advisory Chrome V8 Type Confusion New Sandbox Escape
- Chromereleases Googleblog Technical reference Stable Channel Update For Desktop
- Exploit information from crbug.com
- Lists Fedoraproject Third-party advisory DYTXO5E3FI3I2ETDP3HF4SHYYTFMKMIC
- Lists Fedoraproject Third-party advisory U4OXTNIZY4JYHJT7CVLPAJQILI6BISVM
- Security Gentoo Third-party advisory 202311 11
- Security Gentoo Third-party advisory 202401 34
- Couchbase Third-party advisory Alerts