Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
2023-09-28T16:15:10.980
2025-04-03T18:55:36.100
Analyzed
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | webmproject | libvpx | < 1.13.1 | Yes |
Application | microsoft | edge | 116.0.1938.98 | Yes |
Application | microsoft | edge | 117.0.2045.47 | Yes |
Application | microsoft | edge_chromium | 116.0.5845.229 | Yes |
Application | microsoft | edge_chromium | 117.0.5938.132 | Yes |
Application | mozilla | firefox | < 115.3.1 | Yes |
Application | mozilla | firefox | < 118.0.1 | Yes |
Application | mozilla | firefox | < 118.1 | Yes |
Application | mozilla | thunderbird | < 115.3.1 | Yes |
Operating System | fedoraproject | fedora | 37 | Yes |
Operating System | fedoraproject | fedora | 38 | Yes |
Operating System | fedoraproject | fedora | 39 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Operating System | debian | debian_linux | 11.0 | Yes |
Operating System | debian | debian_linux | 12.0 | Yes |
Operating System | apple | ipados | < 17.0.3 | Yes |
Operating System | apple | ipados | 16.7 | Yes |
Operating System | apple | iphone_os | < 17.0.3 | Yes |
Operating System | apple | iphone_os | 16.7 | Yes |
Application | chrome | < 117.0.5938.132 | Yes | |
Operating System | redhat | enterprise_linux | 9.0 | Yes |