
"CISA Alerts on Active Exploits in Chrome and Excel Library Vulnerabilities"
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of two actively exploited vulnerabilities: a heap buffer overflow in Google Chrome's WebRTC (CVE-2023-7024) and a remote code execution flaw in the Spreadsheet::ParseExcel Perl library (CVE-2023-7101). Federal agencies are required to address these issues by January 23. The Spreadsheet::ParseExcel vulnerability has been exploited by Chinese hackers, notably affecting Barracuda's Email Security Gateway. Google has already issued an emergency update to patch the Chrome vulnerability, marking the eighth zero-day fixed in the browser for the year. CISA's KEV catalog helps organizations prioritize vulnerability management.