Launch Week Day 1: Announcing Security Design Review
HIGH 8.8 npm KEV

Electron affected by libvpx's heap buffer overflow in vp8 encoding

GHSA-qqvq-6xgj-jw8g · CVE-2023-5217

Published · Modified

Description

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes