Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 49.0%; technical severity is CVSS 8.8.
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Who should care
- Teams operating Ipados, Iphone Os, Debian Linux +9 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Ipados, Iphone Os, Debian Linux +9 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Apple Security patch HT213961
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Patch
- Apple Security patch HT213961Apple · Vendor sourceVerification pending ↗
- Apple Security patch HT213972Apple · Vendor sourceVerification pending ↗
- GitHub Security patch 3fbd1dca6a4d2dad332a2110d646e4ffef36d590GitHubVerification pending ↗
- GitHub Security patch Af6dedd715f4307669366944cca6e0417b290282GitHubVerification pending ↗
- Openwall Security patchOpenwallVerification pending ↗
- Openwall Security patchOpenwallVerification pending ↗
Advisory
- Debian Security advisory Msg00038Debian · Vendor sourceVerification pending ↗
- Debian Security advisory Msg00001Debian · Vendor sourceVerification pending ↗
- Debian Security advisory Msg00015Debian · Vendor sourceVerification pending ↗
- Debian Security advisory Dsa 5508Debian · Vendor sourceVerification pending ↗
- Debian Security advisory Dsa 5509Debian · Vendor sourceVerification pending ↗
- Debian Security advisory Dsa 5510Debian · Vendor sourceVerification pending ↗
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- CWE
- CWE-787
- Affected versions
- Apple Ipados (Start Including 17.0, End Excluding 17.0.3 | Version 16.7); Apple Iphone Os (Start Including 17.0, End Excluding 17.0.3 | Version 16.7); Debian Debian Linux (Version 10.0 | Version 11.0 | Version 12.0); Fedoraproject Fedora (Version 37 | Version 38 | Version 39); Google Chrome (End Excluding 117.0.5938.132); Google Chromium libvpx; Microsoft Edge (Version 116.0.1938.98 | Version 117.0.2045.47); Microsoft Edge Chromium (Version 116.0.5845.229 | Version 117.0.5938.132)
- Fixed versions
- Apple Ipados (Fixed from 17.0.3); Apple Iphone Os (Fixed from 17.0.3); Google Chrome (Fixed from 117.0.5938.132); Mozilla Firefox (Fixed from 115.3.1, 118.0.1, 118.1); Mozilla Thunderbird (Fixed from 115.3.1); Webmproject Libvpx (Fixed from 1.13.1)
- Published
- 28 September 2023
- Attack vector
- Network
- Privileges required
- None
- User interaction
- Required
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 49.0%
- Signal calculated at 78
External references
- Red Hat Third-party advisory Show Bug.cgi
- Debian Third-party advisory CVE-2023-5217
- CISA Government advisory CVE-2023-5217
- GitHub Technical reference
- Seclists Third-party advisory
- Seclists Third-party advisory
- Openwall Third-party advisory
- Openwall Third-party advisory
- Openwall Third-party advisory
- Openwall Third-party advisory
- Openwall Third-party advisory
- Openwall Third-party advisory