CVE-2023-2136 is a critical integer overflow vulnerability in Skia, affecting Google Chrome versions prior to 112.0.5615.137, as well as various Debian and Fedora distributions. This flaw allows a remote attacker, after compromising the renderer process, to achieve sandbox escape via a crafted HTML page. With a CVSS score of 9.6 (CRITICAL), it poses a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Notably, this vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has garnered substantial community discussion and media coverage, despite the absence of public exploit code on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 112.0.5615.137CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.