Vulnerability record · CVE-2023-7024 · published 21 December 2023
CVE-2023-7024: Google Chrome WebRTC heap buffer overflow via crafted HTML page
Google · Chrome
Google Chrome before 120.0.6099.129 contains a heap buffer overflow in WebRTC (CWE-787 out-of-bounds write). A remote attacker can trigger heap corruption by getting a victim to open a crafted HTML page. The flaw is rated high severity by Chromium and carries a CVSS 3.1 base score of 8.8.
Description
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a remotely reachable, high-impact memory corruption flaw in a widely deployed browser and is listed in CISA KEV as exploited in the wild.
What it is
Google Chrome before 120.0.6099.129 contains a heap buffer overflow in WebRTC (CWE-787 out-of-bounds write). A remote attacker can trigger heap corruption by getting a victim to open a crafted HTML page. The flaw is rated high severity by Chromium and carries a CVSS 3.1 base score of 8.8.
Impact
Successful exploitation can corrupt the heap, which typically leads to code execution in the browser process or a crash. The CVSS vector indicates high confidentiality, integrity and availability impact.
Attack surface
Reached over the network through a crafted HTML page rendered in Chrome; no privileges are required but user interaction (opening the page) is needed per the CVSS vector AV:N/AC:L/PR:N/UI:R. WebRTC is the affected component, so pages that exercise WebRTC functionality are the relevant path.
Exploitation
CVE-2023-7024 is listed in CISA KEV (added 2024-01-02, due 2024-01-23), indicating known exploitation in the wild. EPSS gives a 30-day probability of 0.07356 (94th percentile), and a reference is tagged Exploit.
What to do
- Update Chrome to 120.0.6099.129 or later, and apply the corresponding Debian (DSA-5585) and Fedora updates for bundled Chromium.
- Track the CISA KEV due date of 2024-01-23 and confirm all exposed endpoints are patched before it.
- If immediate patching is not possible, restrict or disable WebRTC in Chrome via enterprise policy until the browser is updated.
- Inventory Chrome and Chromium-based browsers across the estate, including Linux distributions that ship their own builds, so no unpatched instance is missed.
Detection
- Monitor for Chrome crashes or renderer process terminations consistent with heap corruption, especially following visits to untrusted or newly registered sites.
- Hunt proxy and DNS logs for access to low-reputation or newly registered domains that could host the crafted HTML page.
- Check endpoint telemetry for browser processes spawning unexpected child processes or making anomalous outbound connections after page loads.
- Verify browser version compliance across managed endpoints and alert on any Chrome build older than 120.0.6099.129.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-7024 to the Known Exploited Vulnerabilities catalog on 2 January 2024 as "Google Chromium WebRTC Heap Buffer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 23 January 2024.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-7024 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-7024), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.