CVE-2023-2033highunder attackCWE-843

CVE-2023-2033: high-severity vulnerability in Google Chrome

Published · Updated

85Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 41%
from disclosure to weapon3 days
Published on NVDApr 14
1st PoC+3d
CISA KEV+3d
exploitation probability
41%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
7 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
Action required by CISAfederal deadline: 2023-05-08

Apply updates per vendor instructions.

In short

A type confusion bug in Chrome's V8 engine allows attackers to corrupt heap memory through a specially crafted webpage, potentially leading to code execution or browser crashes.

Technical detail

Type confusion vulnerability in V8 (CWE-843) enables remote code execution via heap corruption when processing malicious HTML. Requires user to visit a crafted webpage; no authentication needed. Impacts confidentiality, integrity, and availability of the browser process.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Google · Chrome
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.