CVE-2023-2136
Google Chrome
Published 19 Apr 2023 · updated 17 Jun 2026 · Analyzed
9.6 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 21 Apr 2023, with a remediation deadline of 12 May 2023 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
References
- chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_18.html · Release Notes, Vendor Advisory
- crbug.com/1432603 · Issue Tracking, Third Party Advisory
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4AOSGAOPXLBK4A5ZRTVZ4M6QKVLSWMWG/ · Mailing List
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ES2CDRHR2Y4WY6DNDIAPYZFXJU3ZBFAV/ · Mailing List
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FEJZMAUB4XP44HSHEBDWEKFGA7DUHY42/ · Mailing List
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IHHD6KNH4WLUE6JG6HRQZWNAJMHJ32X7/ · Mailing List
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RJQI63HWZFL6M26Q6UOHKDY6LD2PFC5Z/ · Mailing List
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SLO7BL2MHZYPY6O3OAEAQL3SKYMGGO6M/ · Mailing List
- security.gentoo.org/glsa/202309-17 · Third Party Advisory
- www.debian.org/security/2023/dsa-5393 · Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-2136 · US Government Resource