CVE-2023-2033: high-severity vulnerability in Google Chrome
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
A type confusion bug in Chrome's V8 engine allows attackers to corrupt heap memory through a specially crafted webpage, potentially leading to code execution or browser crashes.
Type confusion vulnerability in V8 (CWE-843) enables remote code execution via heap corruption when processing malicious HTML. Requires user to visit a crafted webpage; no authentication needed. Impacts confidentiality, integrity, and availability of the browser process.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.