Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
← The Naughty List

Google Chrome

CVE-2023-4863

HIGHActively exploited by attackers

Why this is on the list

Vendor-confirmed: affected range, remediation and fixed version come from the vendor or CNA advisory.

  • CISA added this to its Known Exploited Vulnerabilities Catalog on 2023-09-13.
  • CISA records it as having been used in ransomware campaigns.

Does this apply to your version?

No vendor-confirmed affected range has been published for this finding yet. That means we can confirm the vulnerability is being exploited, but we cannot yet say which releases are affected — and it should not be read as meaning every version is vulnerable, or that any particular version is safe.

Check your version

What to do

Update to 116.0.5845.187 or later.

Vendor
Google
Product
Google Chrome
Fixed in
116.0.5845.187
First published
2026-09-05

Where this comes from

3 sources
  • CISAPrimary government source

    Confirms active exploitation · Informs severity

    Vulnerability is exploited in the wild (CISA KEV listing)

    Read the CISA record
  • CVE RecordCNA-supplied evidence

    Defines affected versions · Defines the fixed release · Determines whether a version is affected

    CNA-published affected versions and remediation

    Read the CVE record
  • FIRSTSupporting intelligence

    Informs severity

    EPSS estimates a >99% probability that this vulnerability will be exploited in the next 30 days. It is a forecast about the vulnerability, not a statement about whether your installation is affected.

    About EPSS

How this was assessed

  • CVE-2023-4863 triggered rule KEV_KNOWN_EXPLOITED
  • CISA KEV lists it as known-exploited
  • EPSS 0.99979
  • Google Chrome affected range confirmed by CNA
  • Patient Protect score 70 (HIGH) under pp-risk-1.0
  • fixed version 116.0.5845.187 provenance: CNA
  • remediation provenance: CNA
  • evidence sufficient

Information provided by Patient Protect's Technology Risk Ledger (“The Naughty List”) is sourced from official vendor and government advisories and is provided “as is” for informational purposes only. Inclusion on The Naughty List identifies a documented technology-security risk based on available evidence at the time of publication; it is not a finding of wrongdoing, negligence, or fault by any vendor. Patient Protect does not warrant the completeness, accuracy, or timeliness of the information. Users are solely responsible for verifying applicability to their specific environment and for their own remediation decisions. Patient Protect disclaims all liability for damages arising from the use of this information.

Do you run this?

Check your own version against the ledger — it may or may not fall inside the affected range.

Check your technology