Get the App
SLTechnology News&Howtos  ›  IT Information  › 

Chrome browser releases emergency update to fix exploited zero-day vulnerability of "CVE-2023-4863"

Shulou Source: shulou.com Published: 2023-11-24 20:38:03 10月03日 Update

Thanks to CTOnews.com netizen Ji Yinkesi for the clue delivery! CTOnews.com September 12, Google has released an emergency security update to fix a zero-day security vulnerability in Chrome.

The company announced in a security bulletin: "Google is aware that vulnerability CVE-2023-4863 has been externally exploited, this issue is described as heap buffer overflow, exists in WebP image format. "

CTOnews.com learned from a query that a heap buffer overflow occurs when a program attempts to write more data to an allocated memory buffer than the buffer is actually designed to hold. In some cases, this vulnerability could allow an attacker to execute arbitrary code on a victim's device.

Apple Security Engineering and Architecture (SEAR) and the Munk College Civic Lab at the University of Toronto discovered and reported the vulnerability to Google on September 6, 2023. However, Google did not disclose details of the vulnerability, only mentioning that the vulnerability had been "externally exploited" and did not provide information on how the attacker exploited the vulnerability.

Google has released Chrome 116.0.5845.187 for Mac / Linux and 116.0.5845.188 for Windows, fixing CVE-2023-4863 and "strongly requesting users to update."

reference

CVE-2023-4863

Chrome Releases - Stable Channel Update for Desktop

Tags: Vulnerabilities security buffers buffers browsing browsing blogs platforms attackers attacks code companies announcements citizens memory victims images University of Toronto Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Information OPPO Reno Microsoft Shulou Tech Info Huawei