What is the Vulnerability?
A zero-day vulnerability in Google Chrome is actively exploited in the wild. The vulnerability is a Heap buffer overflow issue in the open-source WebRTC framework. Many other web browsers, such as Mozilla Firefox, Safari, and Microsoft Edge, also use the WebRTC framework to provide Real-Time Communications (RTC) capabilities. A successful exploitation of the vulnerability via a crafted HTML page could allow an attacker to execute arbitrary code on the affected system.
What is the Vendor Solution?
Google has released security updates to address this high-severity zero-day vulnerability (CVE-2023-7024) in Google Chrome. Chromium-based browsers such as Microsoft Edge are also affected by this vulnerability. Users of Google Chrome are advised to upgrade their browser to the latest version. [ Link ]
What FortiGuard Coverage is available?
FortiGuard Labs is investigating for possible protection where applicable.
FortiGuard Labs has an Endpoint Vulnerability signature for CVE-2023-4966 to detect devices that are running on a vulnerable software.
Meanwhile, users are encouraged to enable automatic updates in their Chrome browser to ensure that their software is updated promptly.
More Stories
webkitgtk-2.48.1-2.fc40
FEDORA-2025-256a86d7c8 Packages in this update: webkitgtk-2.48.1-2.fc40 Update description: Limit the data stored in session state. Remove the empty area below...
webkitgtk-2.48.1-2.fc41
FEDORA-2025-059585d039 Packages in this update: webkitgtk-2.48.1-2.fc41 Update description: Limit the data stored in session state. Remove the empty area below...
webkitgtk-2.48.1-2.fc42
FEDORA-2025-5427adc3f4 Packages in this update: webkitgtk-2.48.1-2.fc42 Update description: Limit the data stored in session state. Remove the empty area below...
chromium-135.0.7049.52-2.el10_1
FEDORA-EPEL-2025-c6f4db8d49 Packages in this update: chromium-135.0.7049.52-2.el10_1 Update description: Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067:...
ZDI-CAN-26891: Amazon
A CVSS score 6.5 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N severity vulnerability discovered by 'Jiri Gogela of Trend Research' was reported to the affected vendor...
USN-7415-1: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This...