Google patches a Chrome zero-day that was exploited by a commercial spyware vendor, just two days after Google's Threat Analysis Group informed the Chrome team
update now! Jai Vijayan / Dark Reading : Chrome Flags Third Zero-Day This Month That's Tied to Spying Exploits Austin Blake / iPhone in Canada Blog : Google Patches Chrome Zero-Day Exploited by Spyware Vendor Steve Zurier / SC Media : Google patches new zero-day actively exploited in the Chrome browser Kevin Poireault / Infosecurity : A Guide to Zero-Day Vulnerabilities and Exploits for the Uninitiated Michael Kan / PCMag : Google Catches Surveillance Company Exploiting Serious Flaw in Chrome Anthony Spadafora / Tom's Guide : Billions at risk from Google Chrome security flaw — update your browser right now Mastodon: Topher / @topher@mastodon.online : Mozilla released #Firefox 118.0.1 and ESR 115.3.1 to address CVE-2023-5217: Heap buffer overflow in libvpx — https://www.mozilla.org/... I suppose I'll follow the Linux distro packages again for this one so I guess follow this thread or whatever 😂 — #security #cve20235217 #libvpx X: Maddie Stone / @maddiestone : .@_clem1 discovered another ITW 0-day in use by a commercial surveillance vendor: CVE-2023-5217. Thank you to Chrome for releasing a patch in TWO 🤯day!! https://chromereleases.googleblog.com/ ... Maddie Stone / @maddiestone : @ChessRadar @_clem1 Industry standard for a non-actively exploited vuln is 90 days so they fixed it in less than a third of the time that is industry standard? @mysk_co : This vulnerability doesn't impact Chrome for iOS. The @AppStore forces browser developers to use WebKit as the browser engine. The browsers affected are those that use Blink as their browser engine. That includes Chrome and Chromium-based browsers. Hossein Lotfi / @hosselot : New Google Chrome In-The-Wild vulnerability used by a commercial surveillance vendor is a buffer overflow in vp8 encoding in libvpx (CVE-2023-5217 [1486441]) and happens due to allowing thread count change after encoder creation: https://chromium.googlesource.com/ ... Forums: r/technology : A new Chrome 0-day is sending the Internet into a new chapter of Groundhog Day
Context & Ripple Effects
This report sits in a recurring Chrome security arc: Google’s Threat Analysis Group had previously identified an actively exploited browser flaw, while a separate 2023 update addressed an in-the-wild V8 type-confusion issue. The notable detail here is the short handoff from threat discovery to a browser-team fix.
Related coverage also records multiple Chrome zero-days patched in a short 2020 stretch and later emergency fixes for actively exploited flaws, including several 2024 zero-day patches within a week. That history makes rapid remediation a central part of Chrome’s response to targeted exploitation.
First-order effects
- Chrome users receive a patch for CVE-2023-5217; applying it closes the reported exploit path used by a commercial surveillance vendor.
- Google’s Threat Analysis Group and Chrome team demonstrate a two-day detection-to-patch handoff, limiting the period in which the known flaw remains available to the reported operator.
Second-order effects
- The surveillance vendor must replace or rework the exploit to maintain browser access, while organizations that delay browser updates retain the avoidable exposure.
- The episode increases the operational value of Google’s threat-research pipeline; earlier TAG-led discovery of an exploited Chrome flaw shows that this is an established defensive channel rather than a one-off response.
Third-order effects
- If commercial spyware vendors continue to use browser zero-days, rapid patch distribution and update adoption become as consequential as initial vulnerability discovery in reducing their usable window.
- The pattern points to a continuing browser-security contest in which well-resourced surveillance actors target widely deployed clients and platform vendors increasingly rely on dedicated threat-intelligence teams to interrupt them.
The trend: Commercial spyware activity is reinforcing a faster detect-disclose-patch cycle for browser zero-days, with endpoint update speed determining how much protection reaches users.