/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google patches a Chrome zero-day that was exploited by a commercial spyware vendor, just two days after Google's Threat Analysis Group informed the Chrome team

update now! Jai Vijayan / Dark Reading : Chrome Flags Third Zero-Day This Month That's Tied to Spying Exploits Austin Blake / iPhone in Canada Blog : Google Patches Chrome Zero-Day Exploited by Spyware Vendor Steve Zurier / SC Media : Google patches new zero-day actively exploited in the Chrome browser Kevin Poireault / Infosecurity : A Guide to Zero-Day Vulnerabilities and Exploits for the Uninitiated Michael Kan / PCMag : Google Catches Surveillance Company Exploiting Serious Flaw in Chrome Anthony Spadafora / Tom's Guide : Billions at risk from Google Chrome security flaw — update your browser right now Mastodon: Topher / @topher@mastodon.online : Mozilla released #Firefox 118.0.1 and ESR 115.3.1 to address CVE-2023-5217: Heap buffer overflow in libvpx  —  https://www.mozilla.org/...  I suppose I'll follow the Linux distro packages again for this one so I guess follow this thread or whatever 😂  —  #security #cve20235217 #libvpx X: Maddie Stone / @maddiestone : .@_clem1 discovered another ITW 0-day in use by a commercial surveillance vendor: CVE-2023-5217. Thank you to Chrome for releasing a patch in TWO 🤯day!! https://chromereleases.googleblog.com/ ... Maddie Stone / @maddiestone : @ChessRadar @_clem1 Industry standard for a non-actively exploited vuln is 90 days so they fixed it in less than a third of the time that is industry standard? @mysk_co : This vulnerability doesn't impact Chrome for iOS. The @AppStore forces browser developers to use WebKit as the browser engine. The browsers affected are those that use Blink as their browser engine. That includes Chrome and Chromium-based browsers. Hossein Lotfi / @hosselot : New Google Chrome In-The-Wild vulnerability used by a commercial surveillance vendor is a buffer overflow in vp8 encoding in libvpx (CVE-2023-5217 [1486441]) and happens due to allowing thread count change after encoder creation: https://chromium.googlesource.com/ ... Forums: r/technology : A new Chrome 0-day is sending the Internet into a new chapter of Groundhog Day

TechCrunch Carly Page

Context & Ripple Effects

This report sits in a recurring Chrome security arc: Google’s Threat Analysis Group had previously identified an actively exploited browser flaw, while a separate 2023 update addressed an in-the-wild V8 type-confusion issue. The notable detail here is the short handoff from threat discovery to a browser-team fix.

Related coverage also records multiple Chrome zero-days patched in a short 2020 stretch and later emergency fixes for actively exploited flaws, including several 2024 zero-day patches within a week. That history makes rapid remediation a central part of Chrome’s response to targeted exploitation.

First-order effects

  • Chrome users receive a patch for CVE-2023-5217; applying it closes the reported exploit path used by a commercial surveillance vendor.
  • Google’s Threat Analysis Group and Chrome team demonstrate a two-day detection-to-patch handoff, limiting the period in which the known flaw remains available to the reported operator.

Second-order effects

  • The surveillance vendor must replace or rework the exploit to maintain browser access, while organizations that delay browser updates retain the avoidable exposure.
  • The episode increases the operational value of Google’s threat-research pipeline; earlier TAG-led discovery of an exploited Chrome flaw shows that this is an established defensive channel rather than a one-off response.

Third-order effects

  • If commercial spyware vendors continue to use browser zero-days, rapid patch distribution and update adoption become as consequential as initial vulnerability discovery in reducing their usable window.
  • The pattern points to a continuing browser-security contest in which well-resourced surveillance actors target widely deployed clients and platform vendors increasingly rely on dedicated threat-intelligence teams to interrupt them.

The trend: Commercial spyware activity is reinforcing a faster detect-disclose-patch cycle for browser zero-days, with endpoint update speed determining how much protection reaches users.

Discussion

  • @topher@mastodon.online Topher on mastodon
    Mozilla released #Firefox 118.0.1 and ESR 115.3.1 to address CVE-2023-5217: Heap buffer overflow in libvpx  —  https://www.mozilla.org/...  I suppose I'll follow the Linux distro packages again for this one so I guess follow this thread or whatever 😂  —  #security #cve20235217 #l…
  • @maddiestone Maddie Stone on x
    .@_clem1 discovered another ITW 0-day in use by a commercial surveillance vendor: CVE-2023-5217. Thank you to Chrome for releasing a patch in TWO 🤯day!! https://chromereleases.googleblog.com/ ...
  • @maddiestone Maddie Stone on x
    @ChessRadar @_clem1 Industry standard for a non-actively exploited vuln is 90 days so they fixed it in less than a third of the time that is industry standard?
  • @mysk_co @mysk_co on x
    This vulnerability doesn't impact Chrome for iOS. The @AppStore forces browser developers to use WebKit as the browser engine. The browsers affected are those that use Blink as their browser engine. That includes Chrome and Chromium-based browsers.
  • @hosselot Hossein Lotfi on x
    New Google Chrome In-The-Wild vulnerability used by a commercial surveillance vendor is a buffer overflow in vp8 encoding in libvpx (CVE-2023-5217 [1486441]) and happens due to allowing thread count change after encoder creation: https://chromium.googlesource.com/ ...
  • r/technology r on reddit
    A new Chrome 0-day is sending the Internet into a new chapter of Groundhog Day