Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
HighCISA KEVExploited in the wildPublic exploit

Type Confusion in V8 in Google Chrome prior to 116.0.5845.179

IdentifiersCVE-2023-4762CWE-843· Access of Resource Using…

Type confusion vulnerability in the V8 JavaScript engine in Google Chrome (Chromium) prior to 116.0.5845.179. The issue can be triggered by a remote attacker via a crafted HTML page, leading to unintended type assumptions during execution and enabling arbitrary code execution in the browser context. Chromium security severity is rated High.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Remote code execution via a crafted HTML page in affected Chrome/Chromium versions (prior to 116.0.5845.179). Successful exploitation can allow execution of attacker-controlled code within the browser process, potentially enabling further compromise depending on sandbox/defense bypasses and local environment.

Mitigation

If you can’t patch tonight, do this now.

Reduce exposure by limiting untrusted web content execution (e.g., restrict browsing to trusted sites, use site isolation where available, and enforce rapid browser patching). Consider additional hardening controls (application allowlisting, EDR/browser exploit protection) to reduce post-exploitation impact; however, patching is the primary mitigation.

Remediation

Patch, then assume compromise.

Update Google Chrome/Chromium to a version that includes the fix (Chrome 116.0.5845.179 or later). Ensure all Chromium-based browsers that embed affected V8 versions are updated to vendor-fixed releases.
PUBLIC EXPLOITS

Exploits

1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.

VALID 1 / 1 TOTALView more in app
CVE-2023-4762MaturityPoCVerified exploit

This repository contains a single JavaScript proof-of-concept (PoC) exploit for CVE-2023-4762, a vulnerability in Google's V8 JavaScript engine. The exploit demonstrates a 'hole' leak bug related to the handling of arguments objects and feedback vectors during the optimization phase in V8's Turbofan pipeline. The code is intended to be run in a debug build of V8 using the d8 shell with specific flags to observe the bug. The PoC does not provide a weaponized payload but serves as a technical demonstration of the vulnerability, which could potentially be leveraged for further exploitation such as type confusion or memory corruption. The repository is well-commented, includes references to the relevant patch and related research, and is structured as a single file (poc.js) containing both technical writeup and exploit code.

buptsbDisclosed Sep 27, 2023javascriptlocal
EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
DebianDebian Linuxoperating_system
Fedora ProjectFedoraoperating_system
GoogleChromeapplication
Microsoft CorporationEdge Chromiumapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures2

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.