CVE-2023-3079PoC(apple / chrome)

LOWCVSS 8.8 · HIGHCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

2.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-06-28. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-843

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • couchbase_server
  • debian_linux
  • fedora

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
chromecouchbase_serverdebian_linuxfedoralinux_kernelmacoswindows

6 versions affected across 7 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-26: 1PoC Mentioned / Linked · 2026-06-26: 1Technical Details · 2026-06-26: 106-26
Signal classification1 categories
PoC
1100.0%
Referenced assets1 URL
Full discourse1 post
  • hackyboiz@hackyboiz2
    PoC

    Hello everyone, this is Hackyboiz 🐣 Last weekend, we posted about the V8 Heap Sandbox Bypass in Chrome, and we truly appreciate the amazing response! Today, we're back with a new post for the Wipeload Project: Step 3 - V8 Remote Code Execution via CVE-2023-3079 Ready to dive in? Let's get it! 🔥 https://hackyboiz.github.io/2026/06/26/ji9umi/%5BWipeload-Step-3%5DH0le-in-One/EN/

    Post summary

    Hackyboiz is releasing a Proof of Concept for V8 Remote Code Execution through CVE-2023-3079, with a link to a demonstration post; no active exploitation or patch information is mentioned.

    04127131.5K
    525 followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appcouchbasecouchbase_server---
Appcouchbasecouchbase_server7.2.0--
OSdebiandebian_linux11.0--
OSdebiandebian_linux12.0--
OSfedoraprojectfedora37--
OSfedoraprojectfedora38--
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more