Open Nav
Sign Up

New Chrome Zero-Day Vulnerability (CVE-2023-7024)

Chrome Zero-Day Vulnerability

Bar Refael

December 26, 2023

We at OP Innovate would like to bring to your immediate attention a critical security update regarding a newly identified vulnerability in the Google Chrome browser, referenced as CVE-2023-7024. This vulnerability has been actively exploited in the wild and demands urgent action.

Key Points of the Vulnerability:

  • Vulnerability Description: CVE-2023-7024 is a high-severity heap buffer overflow issue identified within the WebRTC framework used in Chrome. This flaw could lead to program crashes or arbitrary code execution on affected systems.
  • Discovery: The vulnerability was discovered and reported by Clément Lecigne and Vlad Stolyarov of Google’s Threat Analysis Group (TAG).
  • Exploitation in the Wild: Google has confirmed that this vulnerability has been actively exploited, making it the eighth Chrome zero-day patched in 2023.
  • Other Zero-Day Vulnerabilities: This year has seen several other zero-day vulnerabilities in Chrome, including CVE-2023-6345, CVE-2023-5217, and others, each with its own risk factors.
  • Impact on Cybersecurity: With over 26,000 vulnerabilities disclosed in 2023, this adds to a growing list of security challenges faced by users and organizations.

Recommended Actions:

  • Immediate Update: Users are urged to update their Chrome browsers to the latest versions (120.0.6099.129/130 for Windows and 120.0.6099.129 for Mac and Linux) as soon as possible.
  • Chromium-Based Browsers: Users of browsers based on Chromium (like Microsoft Edge, Brave, Opera, and Vivaldi) should also apply updates when available.

Importance of Timely Action:

  • The rapid response to such vulnerabilities is crucial to safeguarding your digital infrastructure against potential exploits.
  • Delay in updating could leave systems exposed to cyber-attacks, including remote code execution and data breaches.

OP Innovate’s Commitment:

  • We are closely monitoring the situation and will provide further updates as more information becomes available.
  • Our team is dedicated to assisting our customers in navigating these cybersecurity challenges effectively.

Please do not hesitate to reach out to us for any assistance or clarification regarding this update. Your digital safety and security are our top priority.

Stay safe and updated

Resources highlights

Malicious npm Packages Target Developers with Multi-OS Info-Stealer Payloads

A new software supply-chain attack has been uncovered involving ten malicious npm packages designed to steal developer credentials across Windows, macOS, and Linux systems. These…

Read more >

malicious npm packages

Cybersecurity Budgeting for 2026: Getting More Value from Every Dollar

As organizations close the books on 2025, cybersecurity leaders face a familiar dilemma: rising threats, growing expectations and shrinking budgets . Economic uncertainty has tightened…

Read more >

budgeting plan 2026

CVE-2025-59287: WSUS Remote Code Execution

CVE-2025-59287 is a critical remote code execution (RCE) vulnerability in the Windows Server Update Services (WSUS) role. An attacker who can reach a WSUS server…

Read more >

CVE-2025-59287

CVE-2025-33073: Windows SMB Client Improper Access Control Added to CISA’s KEV

CVE-2025-33073 is a high-severity vulnerability in the Windows SMB client that enables an authenticated remote attacker to escalate privileges to NT AUTHORITY\SYSTEM by abusing a…

Read more >

CVE-2025-33073

F5 Breach: Source Code & Vulnerabilities Stolen by Nation-State Actor

In August 2025, U.S. cybersecurity vendor F5 Networks uncovered a long-term intrusion by a nation-state-linked threat actor that compromised its BIG-IP product development and engineering…

Read more >

f5 breach

CVE-2025-41244: Chinese Threat Actors Actively Exploiting VMware Tools & Aria Vulnerability

CVE-2025-41244 (CVSS 7.8) is a local privilege escalation vulnerability in VMware Tools and VMware Aria Operations when the Service Discovery Management Pack (SDMP) is enabled.…

Read more >

CVE-2025-41244
Under Cyber Attack?

Fill out the form and we will contact you immediately.