← Back to browse · API

CVE-2023-5217

Severity
HIGH
CVSS
8.8
EPSS
0.49013
Risk score
77.35
CISA KEV
Yes
PoC
No
Published
2023-10-02
Modified
2023-10-02
First seen
2026-08-07
Aliases
EUVD-2023-2578, GHSA-QQVQ-6XGJ-JW8G
Products
Google:Chrome 117.0.5938.132 <117.0.5938.132, Google:Chromium libvpx, Google:libvpx 1.13.1 <1.13.1
Sources
euvd EUVD-2023-2578
cisa.gov CVE-2023-5217

Description

Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome.

References