Vulnerability record · CVE-2023-2033 · published 14 April 2023
CVE-2023-2033: Google Chrome V8 type confusion enables heap corruption
Google · Chrome
CVE-2023-2033 is a type confusion flaw in the V8 JavaScript engine in Google Chrome prior to 112.0.5615.121. A crafted HTML page can trigger heap corruption, and the record carries a Chromium security severity of High. Because Chrome is widely deployed and the flaw is remotely reachable, it is a serious browser-side risk.
Description
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote, unauthenticated-in-effect browser flaw with high impact, KEV listing and very high EPSS, though it requires user interaction and a patch is available.
What it is
CVE-2023-2033 is a type confusion flaw in the V8 JavaScript engine in Google Chrome prior to 112.0.5615.121. A crafted HTML page can trigger heap corruption, and the record carries a Chromium security severity of High. Because Chrome is widely deployed and the flaw is remotely reachable, it is a serious browser-side risk.
Impact
An attacker who gets a victim to load a crafted page can potentially corrupt the heap, which in a browser engine typically opens the path to code execution in the renderer process. The CVSS vector rates confidentiality, integrity and availability impact as High.
Attack surface
Reached over the network by a crafted HTML page rendered in Chrome; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N). No authentication is needed, but the victim must visit or open the malicious page.
Exploitation
CVE-2023-2033 is listed in CISA KEV with a due date of 2023-05-08, indicating known exploitation, and EPSS gives a 30-day probability of about 0.41 (98.6th percentile). No ransomware campaign use is documented in the record.
What to do
- Update Chrome to 112.0.5615.121 or later, and apply the corresponding vendor updates for Debian, Fedora, Gentoo and Couchbase Server.
- Enforce automatic browser updates and verify installed versions across managed endpoints.
- Restrict or sandbox browsing where feasible and block known malicious sites at the network layer.
- Track the CISA KEV due date and confirm remediation before it lapses.
Detection
- Monitor for Chrome processes spawning unexpected child processes or making anomalous network connections.
- Hunt for crashes or renderer terminations in Chrome consistent with heap corruption.
- Review proxy and DNS logs for access to sites associated with known exploitation of this CVE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-2033 to the Known Exploited Vulnerabilities catalog on 17 April 2023 as "Google Chromium V8 Type Confusion Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 8 May 2023.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-2033 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-2033), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.