Skip to main content

CVE detail

CVE-2023-2136

Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS 9.6 · CriticalBuzz score 61.9KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 61.9

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 28.9 · diversity 8.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
28.9
17 evidence mentions in the snapshot
Diversity score
8.0
3 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
17 source links · newest first
  • More than 60 of the Adobe, Google, Android, Microsoft, Mozilla and Apple zero-days that have come to light since 2016 attributed to spyware vendors.

    newswww.securityweek.comFeb 6, 2024, 10:49 AM
  • Google warns of in-the-wild exploitation of CVE-2023-7024, a new Chrome vulnerability, the eighth documented this year.

    newswww.securityweek.comDec 21, 2023, 9:50 AM
  • Google has released emergency updates to address a new actively exploited zero-day vulnerability in the Chrome browser. Google has released emergency updates to address a new zero-day vulnerability, tracked as CVE-2023-7024, in its web browser Chrome. The flaw has been addressed with the release of version 120.0.6099.129 for Mac,Linux and 120.0.6099.129/130 for Windows which will […]

    newssecurityaffairs.comDec 20, 2023, 11:52 PM
  • Google released security updates to address a new actively exploited zero-day vulnerability, tracked as CVE-2023-6345, in the Chrome browser. Google on Wednesday released security updates to address a new actively exploited zero-day, tracked as CVE-2023-6345, in the Chrome browser. The CVE-2023-5217 is a high-severity integer overflow in Skia. Skia is an open-source 2D graphics library […]

    newssecurityaffairs.comNov 29, 2023, 7:04 PM
  • The latest Chrome security update addresses the seventh exploited zero-day vulnerability documented in the browser in 2023.

    newswww.securityweek.comNov 29, 2023, 12:18 PM
  • Google has rushed to patch a new Chrome zero-day vulnerability, tracked as CVE-2023-5217 and exploited by a spyware vendor.

    newswww.securityweek.comSep 28, 2023, 9:48 AM
  • GOOGLE FIXED THE FIFTH CHROME ZERO-DAY OF 2023Security Affairs

    Google released security updates to address a new actively exploited zero-day vulnerability, tracked as CVE-2023-5217, in the Chrome browser. Google on Wednesday released security updates to address a new actively exploited zero-day flaw in the Chrome browser which is tracked as CVE-2023-5217. The CVE-2023-5217 is a high-severity heap buffer overflow that affects vp8 encoding in […]

    newssecurityaffairs.comSep 28, 2023, 9:08 AM
  • Google has released a Chrome 116 security update to patch CVE-2023-4863, the fourth Chrome zero-day vulnerability documented in 2023.

    newswww.securityweek.comSep 12, 2023, 8:05 AM
  • GOOGLE FIXED THE FOURTH CHROME ZERO-DAY OF 2023Security Affairs

    Google rolled out emergency security updates to address a new Chrome zero-day (CVE-2023-4863) actively exploited in the wild. Google rolled out emergency security updates to address a zero-day vulnerability that has been actively exploited in attacks in the wild since the start of the year. The vulnerability, tracked as CVE-2023-4863, is the fourth actively exploited […]

    newssecurityaffairs.comSep 11, 2023, 9:13 PM
  • Google released July security updates for Android that addressed tens of vulnerabilities, including three actively exploited flaws. July security updates for Android addressed more than 40 vulnerabilities, including three flaws that were actively exploited in targeted attacks. “There are indications that the following may be under limited, targeted exploitation.” reads the security bulletin. The CVE-2023-26083 is […]

    newssecurityaffairs.comJul 8, 2023, 5:34 PM
  • Google’s July 2023 security updates for Android patches 43 vulnerabilities, including three exploited in the wild.

    newswww.securityweek.comJul 6, 2023, 1:34 PM
  • In July’s update for the Android operating system (OS), Google has patched 43 vulnerabilities, three of which are actively exploited zero-day…

    newswww.malwarebytes.comJul 5, 2023, 5:00 PM
  • Google fixed the third Chrome zero-day of 2023Security Affairs

    Google released security updates to address a high-severity zero-day flaw in the Chrome web browser that it actively exploited in the wild. Google released security updates to address a high-severity vulnerability, tracked as CVE-2023-3079, in its Chrome web browser. The vulnerability is a type confusion issue that resides in the V8 JavaScript engine. The IT […]

    newssecurityaffairs.comJun 6, 2023, 12:50 PM
  • US Cybersecurity and Infrastructure Security Agency (CISA) added MinIO, PaperCut, and Chrome vulnerabilities to its Known Exploited Vulnerabilities catalog. U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the following three new issues to its Known Exploited Vulnerabilities Catalog: According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have […]

    newssecurityaffairs.comApr 22, 2023, 6:28 PM
  • Update now, there’s a Chrome zero-day in the wildMalwarebytes Labs

    Google has announced an important update for Chrome to help fend off a zero-day. The update fixes several issues, and readers…

    newswww.malwarebytes.comApr 20, 2023, 5:00 PM
  • Google rolled out emergency security patches to address another actively exploited high-severity zero-day flaw in the Chrome browser. Google rolled out emergency fixes to address another actively exploited high-severity zero-day flaw, tracked as CVE-2023-2136, in its Chrome web browser. The vulnerability is an Integer overflow in the Skia graphics library, the issue was reported by […]

    newssecurityaffairs.comApr 19, 2023, 5:33 PM
  • Google warns of another zero-day vulnerability in Chrome, only days after addressing a similar issue.

    newswww.securityweek.comApr 19, 2023, 11:14 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence