CVE-2023-7024
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
6 articles
EPSS Score
Source: FIRST.org · 2026-05-24
3.07%
probability
This CVE has a 3.07% probability
of being exploited in the next 30 days.
0%
Top 86.9th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroHeap overflow in WebRTC
Attack Intelligence
Google Project Zero
Discovered
Dec. 19, 2023
Patched
Dec. 20, 2023
Reported by
Clément Lecigne and Vlad Stolyarov of Google's Threat Analysis Group
Root Cause Analysis
???
Google fixes first actively exploited Chrome zero-day of 2024
BleepingComputer
Jan 16, 2024
Google fixes 8th Chrome zero-day exploited in attacks this year
BleepingComputer
Dec 20, 2023
Security Advisory 2023-100
CERT-EU
Dec 22, 2023
Signal Intelligence
Confidence
92%
EPSS
3.07%
Mentions
6
Last Seen
Jan 16, 2024
CNA Information
Analyst Note
CVE-2023-7024 is a high-severity heap buffer overflow in Chrome WebRTC that was actively exploited in the wild, as confirmed by multiple credible sources including BleepingComputer reporting it as the first actively exploited Chrome zero-day of 2024. The vulnerability has official Google/Chromium documentation, a high CVSS score of 8.8, and evidence of real-world exploitation, supporting the confirmed classification.
Triage Info
Decided atMar 03, 2026