Vulnerability record · CVE-2023-5217 · published 28 September 2023
CVE-2023-5217: libvpx VP8 encoding heap buffer overflow exploited via crafted HTML
Webmproject · Libvpx
A heap buffer overflow in the VP8 encoder in libvpx affects Google Chrome before 117.0.5938.132 and libvpx 1.13.1, and is reachable through a crafted HTML page. Because libvpx is embedded in many browsers and applications, the same flaw propagates across Chrome, Edge, Firefox, Thunderbird and multiple Linux distributions. It matters because it allows heap corruption that can be turned into code execution in the context of the affected process.
Description
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityActive exploitation is confirmed by CISA KEV and high EPSS, and the flaw enables code execution, though it requires user interaction to trigger.
What it is
A heap buffer overflow in the VP8 encoder in libvpx affects Google Chrome before 117.0.5938.132 and libvpx 1.13.1, and is reachable through a crafted HTML page. Because libvpx is embedded in many browsers and applications, the same flaw propagates across Chrome, Edge, Firefox, Thunderbird and multiple Linux distributions. It matters because it allows heap corruption that can be turned into code execution in the context of the affected process.
Impact
An attacker who gets a victim to load a crafted page can corrupt heap memory and potentially execute code with the privileges of the browser or application. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network by rendering a crafted HTML page that triggers VP8 encoding; no authentication is required but user interaction (opening the page) is needed per the CVSS vector. The flaw sits in the libvpx encoder, so any product embedding that library is exposed.
Exploitation
CVE-2023-5217 is listed in CISA KEV with a due date of 2023-10-23, and EPSS gives a 30-day probability of about 0.49 (98.8th percentile), indicating active exploitation. A reference is tagged Exploit, and no ransomware campaign use is documented.
What to do
- Update Google Chrome to 117.0.5938.132 or later and libvpx to 1.13.1 or later; apply vendor patches for Edge, Firefox, Thunderbird, and Linux distributions.
- Track the CISA KEV due date of 2023-10-23 and confirm all exposed browsers and applications are remediated or removed from service.
- Inventory software that bundles libvpx, including non-browser applications, and patch or isolate those that cannot be updated.
- Where patching is not immediately possible, reduce exposure by restricting browsing to trusted sites and blocking untrusted HTML content at the gateway.
- Monitor vendor advisories for updated builds, since fixes were released across multiple vendors rather than a single product.
Detection
- Hunt for browser or application crashes consistent with heap corruption in libvpx VP8 encoding paths.
- Monitor for processes loading outdated libvpx or browser versions below the fixed releases.
- Review web proxy and DNS logs for access to known exploit-hosting or malvertising infrastructure tied to this campaign.
- Correlate endpoint telemetry for unusual child processes or memory manipulation originating from browser processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-5217 to the Known Exploited Vulnerabilities catalog on 2 October 2023 as "Google Chromium libvpx Heap Buffer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 23 October 2023.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-5217 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-5217), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.