CVE-2023-5217

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: Feb. 18, 2026 21 articles

EPSS Score

Source: FIRST.org · 2026-05-24
4.98%
probability
This CVE has a 4.98% probability of being exploited in the next 30 days.
0% Top 89.8th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Heap buffer overflow in vp8 encoding in libvpx

Attack Intelligence

Google Project Zero

Discovered
Sept. 25, 2023
Patched
Sept. 27, 2023
Reported by
Clément Lecigne of Google's Threat Analysis Group
Root Cause Analysis
???

Exploits & PoC

UT-Security/cve-2023-5217-poc

A PoC to trigger CVE-2023-5217 from the Browser WebCodecs or MediaRecorder interface.

17
Trinadh465/platform_external_libvpx_v1.8.0_CVE-2023-5217

PoC CVE-2023-5217 — Trinadh465/platform_external_libvpx_v1.8.0_CVE-2023-5217

0
Trinadh465/platform_external_libvpx_v1.4.0_CVE-2023-5217

PoC CVE-2023-5217 — Trinadh465/platform_external_libvpx_v1.4.0_CVE-2023-5217

0
3 repos — triés par ⭐ Rechercher sur GitHub ↗
Security Advisory 2023-063
CERT-EU Sep 28, 2023

Signal Intelligence

Confidence
92%
EPSS 4.98%
Mentions 21
Last Seen Mar 11, 2025

CNA Information

Analyst Note

CVE-2023-5217 is a high-severity heap buffer overflow in Chrome's VP8 encoding with CVSS 8.8, confirmed by Google and documented in Project Zero. The vulnerability has been actively exploited in the wild and fixed in Chrome 117.0.5938.132, with multiple credible security sources reporting on the vulnerability and its exploitation.

Triage Info

Decided atFeb 18, 2026