What is the Vulnerability?
A zero-day vulnerability in Google Chrome is actively exploited in the wild. The vulnerability is a Heap buffer overflow issue in the open-source WebRTC framework. Many other web browsers, such as Mozilla Firefox, Safari, and Microsoft Edge, also use the WebRTC framework to provide Real-Time Communications (RTC) capabilities. A successful exploitation of the vulnerability via a crafted HTML page could allow an attacker to execute arbitrary code on the affected system.
What is the Vendor Solution?
Google has released security updates to address this high-severity zero-day vulnerability (CVE-2023-7024) in Google Chrome. Chromium-based browsers such as Microsoft Edge are also affected by this vulnerability. Users of Google Chrome are advised to upgrade their browser to the latest version. [ Link ]
What FortiGuard Coverage is available?
FortiGuard Labs is investigating for possible protection where applicable.
FortiGuard Labs has an Endpoint Vulnerability signature for CVE-2023-4966 to detect devices that are running on a vulnerable software.
Meanwhile, users are encouraged to enable automatic updates in their Chrome browser to ensure that their software is updated promptly.
More Stories
xz-5.8.1-1.fc40
FEDORA-2025-258ab1c008 Packages in this update: xz-5.8.1-1.fc40 Update description: New upstream version 5.8.1 Read More
xz-5.8.1-1.fc41
FEDORA-2025-fec4b37bc7 Packages in this update: xz-5.8.1-1.fc41 Update description: New upstream version 5.8.1 Read More
xz-5.8.1-1.fc42
FEDORA-2025-76264ecf04 Packages in this update: xz-5.8.1-1.fc42 Update description: New upstream version 5.8.1 Read More
USN-7414-1: XZ Utils vulnerability
Harri K. Koskinen discovered that XZ Utils incorrectly handled the threaded xz decoder. If a user or automated system were...
chromium-135.0.7049.52-2.fc40
FEDORA-2025-609ed3aaa7 Packages in this update: chromium-135.0.7049.52-2.fc40 Update description: Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067:...
chromium-135.0.7049.52-1.fc41
FEDORA-2025-98dd4c4639 Packages in this update: chromium-135.0.7049.52-1.fc41 Update description: Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067:...