Junglewise Threat Intelligence

CVE-2023-2136: Google Chrome Skia Integer Overflow Vulnerability

CVE-2023-2136 · Severity: critical · CVSS 9.6 · Exploited in the wild · Published 2023-04-21

Technologies: Google Chrome, Google Android, Google ChromeOS, Google Skia. Vendors: Google.

Executive brief

An integer overflow vulnerability in the Skia graphics library used in Google Chrome allows a remote attacker to potentially perform a sandbox escape. The exploit requires the attacker to have already compromised the renderer process and is triggered via a crafted HTML page.

Affected products

  • Google Chrome prior to 112.0.5615.137
  • Google Skia
  • Google ChromeOS
  • Google Android
  • Google Flutter

Timeline

  • 2023-04-18: patched: Stable channel update for desktop released (112.0.5615.137)
  • 2023-04-21: disclosed: NVD publication date
  • 2023-04-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-04-21: exploited: Reported as exploited in the wild per CISA KEV and advisory metadata

Related threats