← Vulnerability feed

Vulnerability record · CVE-2023-5217 · published 28 September 2023

CVE-2023-5217: libvpx VP8 encoding heap buffer overflow exploited via crafted HTML

Webmproject · Libvpx

A heap buffer overflow in the VP8 encoder in libvpx affects Google Chrome before 117.0.5938.132 and libvpx 1.13.1, and is reachable through a crafted HTML page. Because libvpx is embedded in many browsers and applications, the same flaw propagates across Chrome, Edge, Firefox, Thunderbird and multiple Linux distributions. It matters because it allows heap corruption that can be turned into code execution in the context of the affected process.

8.8 CVSS 3.1 High CISA KEV since 2 Oct 2023 EPSS 49% · top 1.2% CWE-787 · Out-of-bounds write
8.8CVSS 3.1 base score
49%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
11Affected product versions listed by NVD
105References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityActive exploitation is confirmed by CISA KEV and high EPSS, and the flaw enables code execution, though it requires user interaction to trigger.

What it is

A heap buffer overflow in the VP8 encoder in libvpx affects Google Chrome before 117.0.5938.132 and libvpx 1.13.1, and is reachable through a crafted HTML page. Because libvpx is embedded in many browsers and applications, the same flaw propagates across Chrome, Edge, Firefox, Thunderbird and multiple Linux distributions. It matters because it allows heap corruption that can be turned into code execution in the context of the affected process.

Impact

An attacker who gets a victim to load a crafted page can corrupt heap memory and potentially execute code with the privileges of the browser or application. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reached over the network by rendering a crafted HTML page that triggers VP8 encoding; no authentication is required but user interaction (opening the page) is needed per the CVSS vector. The flaw sits in the libvpx encoder, so any product embedding that library is exposed.

Exploitation

CVE-2023-5217 is listed in CISA KEV with a due date of 2023-10-23, and EPSS gives a 30-day probability of about 0.49 (98.8th percentile), indicating active exploitation. A reference is tagged Exploit, and no ransomware campaign use is documented.

What to do

  • Update Google Chrome to 117.0.5938.132 or later and libvpx to 1.13.1 or later; apply vendor patches for Edge, Firefox, Thunderbird, and Linux distributions.
  • Track the CISA KEV due date of 2023-10-23 and confirm all exposed browsers and applications are remediated or removed from service.
  • Inventory software that bundles libvpx, including non-browser applications, and patch or isolate those that cannot be updated.
  • Where patching is not immediately possible, reduce exposure by restricting browsing to trusted sites and blocking untrusted HTML content at the gateway.
  • Monitor vendor advisories for updated builds, since fixes were released across multiple vendors rather than a single product.

Detection

  • Hunt for browser or application crashes consistent with heap corruption in libvpx VP8 encoding paths.
  • Monitor for processes loading outdated libvpx or browser versions below the fixed releases.
  • Review web proxy and DNS logs for access to known exploit-hosting or malvertising infrastructure tied to this campaign.
  • Correlate endpoint telemetry for unusual child processes or memory manipulation originating from browser processes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-5217 to the Known Exploited Vulnerabilities catalog on 2 October 2023 as "Google Chromium libvpx Heap Buffer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 23 October 2023.

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://seclists.org/fulldisclosure/2023/Oct/12 Mailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2023/Oct/16 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/28/5 Mailing ListPatchThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/28/6 Mailing ListPatchThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/29/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/29/11 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/29/12 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/29/14 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/29/2 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/29/7 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/29/9 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/30/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/30/2 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/30/3 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/30/4 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/30/5 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/01/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/01/2 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/01/5 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/02/6 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/03/11 Mailing ListThird Party Advisory
https://arstechnica.com/security/2023/09/new-0-day-in-chrome-and-firefox-is-likely-to-plague-other-software/ Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2241191 Issue TrackingThird Party Advisory
https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html Vendor Advisory
https://crbug.com/1486441 ExploitIssue Tracking
https://github.com/webmproject/libvpx/commit/3fbd1dca6a4d2dad332a2110d646e4ffef36d590 Patch
https://github.com/webmproject/libvpx/commit/af6dedd715f4307669366944cca6e0417b290282 Patch
https://github.com/webmproject/libvpx/releases/tag/v1.13.1 Release Notes
https://github.com/webmproject/libvpx/tags Product
https://lists.debian.org/debian-lts-announce/2023/09/msg00038.html Mailing List
https://lists.debian.org/debian-lts-announce/2023/10/msg00001.html Mailing List
https://lists.debian.org/debian-lts-announce/2023/10/msg00015.html Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/4MFWDFJSSIFKWKNOCTQCFUNZW Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/55YVCZNAVY3Y5E4DWPWMX2SPK Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/AY642Z6JZODQJE7Z62CFREVUH Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/BCVSHVX2RFBU3RMCUFSATVQEJ Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/CWEJYS5NC7KVFYU3OAMPKQDYN Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/TE7F54W5O5RS4ZMAAC7YK3CZW Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/WTRUIS3564P7ZLM2S2IH4Y4KZ Mailing List
https://pastebin.com/TdkC4pDv Not Applicable

Track CVE-2023-5217 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-43300Apple iOS, iPadOS and macOS out-of-bounds write via malicious imageAn out-of-bounds write in Apple iOS, iPadOS and macOS is triggered when processing a malicious image file, causing memory corruption. Apple states th…KEVEPSS 22%analysed10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2025-24085Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS Use-After-Free Privilege EscalationA use-after-free flaw in Apple's operating systems was fixed through improved memory management in iOS 18.3, iPadOS 18.3 and 17.7.6, macOS Sequoia 15…KEVEPSS 18%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-10585Google Chrome V8 type confusion enables heap corruptionChrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that can lead to heap corruption when processing a crafted HTML page. It affec…KEVEPSS 5.4%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed

Source: NIST National Vulnerability Database (record CVE-2023-5217), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.