No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Chrome Flags Third Zero-Day This Month That’s Tied to Spying Exploits

September 29, 2023
in Protection
0
informa



Google has fixed a zero-day vulnerability in its Chrome browser that a commercial vendor has already been actively exploiting to drop surveillance software on target systems.

And it’s the third Chrome zero-day bug that Google has disclosed in recent days that’s connected to spying activity.

Memory Corruption Vulnerabilities

The new buffer overflow issue that Google is tracking as CVE-2023-5217 stems from the implementation of a video compression format in a software library that Chrome uses. The flaw is remotely exploitable and gives attackers a way to gain remote code execution on a target system by manipulating heap memory via a maliciously crafted HTML page. It is present in versions of Google Chrome prior to 117.0.5938.132 and versions of the libvpx library before 1.13.1.

Google’s Chrome team credited a member of the company’s Threat Analysis Group (TAG) for discovering and reporting the zero-day threat on Sept. 25. The company issued a patch for it on Sept. 27. In a post on X, formerly Twitter, TAG security researcher Maddie Stone described the bug as a zero-day that a commercial surveillance vendor was exploiting at the time of patch release.

Stone’s tweet did not identify the vendor by name, but in recent days Google has pointed to a surveillance vendor named Intellexa as abusing a previous Chrome zero-day (CVE-2023-4762) to drop a spying tool called Predator on target Android devices in Egypt. Google patched that bug on Sept. 5 after a security researcher notified the company about the threat.

A Flurry of Zero-Days

CVE-2023-5217 is actually the sixth zero-day vulnerability that Google has disclosed in Chrome this year. It is the third vulnerability the company has rushed to patch just this month that appears connected to spying activity.

On Sept. 11, Google disclosed a critical vulnerability identified as CVE-2023-4863 that affected Google Chrome versions for Windows, macOS, and Linux. The buffer overflow vulnerability, in a Chrome library related to image processing (libwebp), gave attackers a way to write arbitrary code on target systems using maliciously crafted HTML images. Google identified CVE-2023-4863 as a vulnerability that attackers were already exploiting, but did not offer any details.

Google discovered the vulnerability after researchers at Apple and the University of Toronto’s The Citizen Lab notified the company about finding a security issue in libwebp that an attacker had abused to drop the notorious Pegasus spyware on target iPhones. Though Google and Apple have assigned different CVEs — Apple’s identifier for the libwebp bug is CVE-2023-41064 — some security researchers have said it is likely that the bugs are essentially the same since they exist in the same library and have identical characteristics.

In addition to these three zero-days, Google disclosed three other Chrome bugs this year that attackers were actively exploiting before the company had a patch for them.

In June, Google disclosed CVE-2023-3079, a so-called type confusion error in the V8 JavaScript engine in Chrome that an attacker could exploit via a specially crafted HTML page. Google disclosed the other two zero-days in April. One was an integer overflow issue in the Skia open source graphics library, tracked as CVE-2023-2136, and the other is CVE-2023-2033, also a type confusion error in V8 that an attacker can exploit via a malicious HTML page. Threat actors were actively exploiting all three vulnerabilities at the time of patching.



Editorial Team

Editorial Team

Related Posts

The Emergency Repair Supplies Every Homeowner Should Have on Hand
Protection

The Emergency Repair Supplies Every Homeowner Should Have on Hand

January 21, 2026
Google Just Promised No Ads in Gemini (for Now)
Protection

Google Just Promised No Ads in Gemini (for Now)

January 21, 2026
This 'Ad Blocker' Actually Initiates ClickFix Attacks
Protection

This ‘Ad Blocker’ Actually Initiates ClickFix Attacks

January 21, 2026
Here's How Netflix Plans to Add TikTok-Style Videos to Its Mobile App
Protection

Here’s How Netflix Plans to Add TikTok-Style Videos to Its Mobile App

January 21, 2026
The Samsung Odyssey OLED G9 Is Nearly $400 Off
Protection

The Samsung Odyssey OLED G9 Is Nearly $400 Off

January 21, 2026
Sony's Newest Earbuds Are Clip-Ons
Protection

Sony’s Newest Earbuds Are Clip-Ons

January 21, 2026
Load More
Next Post
Nvidia, Other Chip Stocks Had a Bad September. Wall Street Remains Upbeat.

Nvidia, Other Chip Stocks Had a Bad September. Wall Street Remains Upbeat.

Popular News

  • Cybersecurity dominates concerns among the C-suite, small businesses and the nation

    Cybersecurity dominates concerns among the C-suite, small businesses and the nation

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Cash Sweep Accounts vs. Money Market Funds, HYSAs & CDs

    0 shares
    Share 0 Tweet 0
  • 5 Things to Know About the Seen Mastercard

    0 shares
    Share 0 Tweet 0
  • TAP Airline Portugal Partners: What to Know

    0 shares
    Share 0 Tweet 0

Latest News

39 Best Airbnbs in Europe for Every Kind of Escape, From Aurora Chasing to Island Hopping

39 Best Airbnbs in Europe for Every Kind of Escape, From Aurora Chasing to Island Hopping

January 21, 2026
0

Number of guests: 4Bed and bath: 2 bedrooms, 1 bathWhy we love it: Lake view, electric bikes, heated pool, saunaThis...

As gold retreats, here’s what’s needed to push prices back toward $5,000

As gold retreats, here’s what’s needed to push prices back toward $5,000

January 21, 2026
0

A big change in the news on Wednesday afternoon may have slowed gold’s prospects for reaching $5,000 an ounce any...

The Emergency Repair Supplies Every Homeowner Should Have on Hand

The Emergency Repair Supplies Every Homeowner Should Have on Hand

January 21, 2026
0

We may earn a commission from links on this page.So many things can go wrong with your home at any...

Vitalik Buterin Says He Will Return Fully to Decentralized Social in 2026

Vitalik Buterin Says He Will Return Fully to Decentralized Social in 2026

January 21, 2026
0

Ethereum co-founder Vitalik Buterin said he plans to fully recommit to decentralized social media in 2026, arguing that only platforms...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.