CVE-2023-2136

CVE Published 2023-04-19
Related CWE(s) CWE-190: Integer Overflow or Wraparound
Related Vendor(s) fedoraproject, debian, google
Related Product(s) fedora, chrome, debian_linux
Exploitation Reported (CISA KEV) 2023-04-21
CVSS 3 Base Score 9.6 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Threat Reports Related to CVE-2023-2136

Report

We're All in this Together - A Year in Review of Zero-Days Exploited In-the-Wild in 2023

This report from Mandiant and Google Threat Analysis Group (TAG) presents combined analysis of zero day vulnerability exploitation in 2023. The ...

Associated CAPEC Patterns

References