{
    "file_item": {
        "filepath": "security-advisories",
        "filename": "CERT-EU-SA2023-035.pdf"
    },
    "title": "Type Confusion Flaw in Google Chrome",
    "serial_number": "2023-035",
    "publish_date": "06-06-2023 15:42:20",
    "description": "Google has released a security update to address a zero-day vulnerability in its Chrome web browser, identified as \"CVE-2023-3079\". The high-severity flaw is a type confusion issue within the V8 JavaScript engine. Google is aware that an exploit for this vulnerability exists in the wild.<br>\nUsers of Google Chrome are strongly advised to update to the latest version to mitigate potential threats.<br>\n",
    "url_title": "2023-035",
    "content_markdown": "--- \ntitle: 'Type Confusion Flaw in\u00a0Google\u00a0Chrome' \nversion: '1.0'\nnumber: '2023-035'\noriginal_date: 'June 5, 2023'\ndate: 'June 6, 2023'\n---\n\n_History:_\n\n* _06/06/2023 --- v1.0 -- Initial publication_\n\n# Summary\n\nGoogle has released a security update to address a _zero-day_ vulnerability in its Chrome web browser, identified as `CVE-2023-3079`. The high-severity flaw is a type confusion issue within the V8 JavaScript engine. Google is aware that **an exploit for this vulnerability exists in the wild**.\n\nUsers of Google Chrome are strongly advised to update to the latest version to mitigate potential threats.\n\n# Technical Details\n\n`CVE-2023-3079` is a type confusion vulnerability in the V8 JavaScript engine used by Google Chrome and other Chromium-based web browsers. Type confusion issues can lead to a crash of the application, or code execution when a user visits a specially crafted and malicious HTML page.\n\nAlthough Google acknowledged the existence of an exploit for `CVE-2023-3079` in the wild, the company has not provided further technical details or indicators of compromise (IoCs) to prevent additional exploitation by threat actors.\n\n# Affected Products\n\nThe following products are affected by `CVE-2023-3079`:\n\n- Google Chrome prior to version `114.0.5735.110` for Windows, and prior to version `114.0.5735.106` for Linux and Mac.\n\n# Recommendations\n\nTo mitigate the risks associated with `CVE-2023-3079`, users are advised to:\n\n- Update Google Chrome to the latest version.\n\n# References\n\n[1] <https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop.html>",
    "content_html": "<p><em>History:</em></p><ul><li><em>06/06/2023 --- v1.0 -- Initial publication</em></li></ul><h2 id=\"summary\">Summary</h2><p>Google has released a security update to address a <em>zero-day</em> vulnerability in its Chrome web browser, identified as <code>CVE-2023-3079</code>. The high-severity flaw is a type confusion issue within the V8 JavaScript engine. Google is aware that <strong>an exploit for this vulnerability exists in the wild</strong>.</p><p>Users of Google Chrome are strongly advised to update to the latest version to mitigate potential threats.</p><h2 id=\"technical-details\">Technical Details</h2><p><code>CVE-2023-3079</code> is a type confusion vulnerability in the V8 JavaScript engine used by Google Chrome and other Chromium-based web browsers. Type confusion issues can lead to a crash of the application, or code execution when a user visits a specially crafted and malicious HTML page.</p><p>Although Google acknowledged the existence of an exploit for <code>CVE-2023-3079</code> in the wild, the company has not provided further technical details or indicators of compromise (IoCs) to prevent additional exploitation by threat actors.</p><h2 id=\"affected-products\">Affected Products</h2><p>The following products are affected by <code>CVE-2023-3079</code>:</p><ul><li>Google Chrome prior to version <code>114.0.5735.110</code> for Windows, and prior to version <code>114.0.5735.106</code> for Linux and Mac.</li></ul><h2 id=\"recommendations\">Recommendations</h2><p>To mitigate the risks associated with <code>CVE-2023-3079</code>, users are advised to:</p><ul><li>Update Google Chrome to the latest version.</li></ul><h2 id=\"references\">References</h2><p>[1] <a rel=\"noopener\" target=\"_blank\" href=\"https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop.html\">https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop.html</a></p>",
    "licence": {
        "title": "Creative Commons Attribution 4.0 International (CC-BY 4.0)",
        "link": "https://creativecommons.org/licenses/by/4.0/",
        "restrictions": "https://cert.europa.eu/legal-notice",
        "author": "The Cybersecurity Service for the Union institutions, bodies, offices and agencies"
    }
}