CVE-2023-5217: Google Chromium libvpx Heap Buffer Overflow Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2023-10-02. EPSS: 49% chance of exploitation in the next 30 days.

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Affected products

  • Apple iPadOS: from 17.0, before 17.0.3 (fixed in 17.0.3); version 16.7 only
  • Apple iPhone OS: from 17.0, before 17.0.3 (fixed in 17.0.3); version 16.7 only
  • Debian Debian Linux: version 10.0 only; version 11.0 only; version 12.0 only
  • Fedoraproject Fedora: version 37 only; version 38 only; version 39 only
  • Google Chrome: before 117.0.5938.132 (fixed in 117.0.5938.132)
  • Microsoft Edge: version 116.0.1938.98 only; version 117.0.2045.47 only
  • Microsoft Edge Chromium: version 116.0.5845.229 only; version 117.0.5938.132 only
  • Mozilla Firefox: before 115.3.1 (fixed in 115.3.1); before 118.0.1 (fixed in 118.0.1); before 118.1 (fixed in 118.1)
  • Mozilla Thunderbird: before 115.3.1 (fixed in 115.3.1)
  • Red Hat Enterprise Linux: version 9.0 only
  • Webmproject Libvpx: before 1.13.1 (fixed in 1.13.1)

Published 2023-09-28. Last modified 2026-06-17.