Researchers detailed how CVE-2023-3079 enabled remote code execution in the Chrome renderer through a type confusion flaw in the V8 JavaScript engine. The bug involved incorrect inline cache handling for property writes to JSStrictArgumentsObject, where the StoreFastElementIC_GrowNoTransitionHandleCOW handler could grow an elements backing store without changing the object from PACKED_ELEMENTS to HOLEY_ELEMENTS, creating an inconsistent internal state.
That inconsistency exposed V8’s internal "The Hole" value to JavaScript, which should remain inaccessible, and the leaked value was then used to trigger a Turbofan JIT type inference error that removed bounds checks. The resulting out-of-bounds array access gave attackers the primitives needed for addr_of and arbitrary read/write, forming the first stage of a broader exploit chain that later pursued sandbox escape and privilege escalation in Chrome.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Theori's writeup identifies CVE-2023-3079 as a Chrome renderer remote code execution vulnerability in the V8 JavaScript engine and describes it as an N-day used as the first stage of an exploit chain. The reference explicitly anchors the flaw to 2023 via its CVE identifier, but does not provide a more specific event date in the content.
Theori published a detailed blog post explaining how CVE-2023-3079 in V8 could be exploited to leak the internal 'The Hole' value, trigger a Turbofan type inference mistake, and achieve out-of-bounds access leading toward code execution. The post presents the bug as the first stage of a broader full-chain exploit demonstration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.