CRITICAL

CVE-2023-2136

Google Chrome 2023-04-19 CVSS v3.1
CVSS
9.6
KEV

Description

Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Summary dbcve.org

This is an integer overflow vulnerability in Skia, Google's 2D graphics rendering library used by Chrome. A remote attacker who has already compromised the Chrome renderer process (e.g., via a separate vulnerability) can exploit this integer overflow through a specially crafted HTML page to escape Chrome's sandbox and execute code at higher privilege levels on the user's system.

Mitigation

Update Google Chrome to version 112.0.5615.137 or later. Organizations should prioritize patch deployment given the high CVSS score and the potential for this vulnerability to be chained with renderer exploits for complete system compromise.

Weakness (CWE)

CWE-190 Integer Overflow

EPSS Score

5.74%
Probability of exploitation in next 30 days
92.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE