Google has released emergency updates to address a new actively exploited zero-day vulnerability in the Chrome browser.

20-Dec-23

The WebRTC vulnerability is a heap buffer overflow. On December 19, 2023, Clément Lecigne and Vlad Stolyarov of Google’s Threat Analysis Group discovered the vulnerability, which was quickly resolved. Heap buffer overflow in WebRTC (CVE-2023-7024). The advice released by the tech behemoth states, “Reported by Clément Lecigne and Vlad Stolyarov of Google’s Threat Analysis Group on 2023-12-19.” “Google is aware that there is a live exploit for CVE-2023-7024.”



Given that Google TAG found the problem, it is likely that a monitoring company or a nation-state actor took use of it.


As per usual, Google withheld information regarding the assaults that took use of the vulnerability in the wild. Since the beginning of, Google has patched eight vulnerabilities, including this one.

Read More…