CVE-2023-2136
Description
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Summary dbcve.org
This is an integer overflow vulnerability in Skia, Google's 2D graphics rendering library used by Chrome. A remote attacker who has already compromised the Chrome renderer process (e.g., via a separate vulnerability) can exploit this integer overflow through a specially crafted HTML page to escape Chrome's sandbox and execute code at higher privilege levels on the user's system.
Mitigation
Update Google Chrome to version 112.0.5615.137 or later. Organizations should prioritize patch deployment given the high CVSS score and the potential for this vulnerability to be chained with renderer exploits for complete system compromise.