CVE detail
CVE-2023-2136
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 28.9 · diversity 8.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
17 source links · newest first
More than 60 of the Adobe, Google, Android, Microsoft, Mozilla and Apple zero-days that have come to light since 2016 attributed to spyware vendors.
newswww.securityweek.comFeb 6, 2024, 10:49 AMGoogle warns of in-the-wild exploitation of CVE-2023-7024, a new Chrome vulnerability, the eighth documented this year.
newswww.securityweek.comDec 21, 2023, 9:50 AM- Google addressed a new actively exploited Chrome zero-daySecurity Affairs
Google has released emergency updates to address a new actively exploited zero-day vulnerability in the Chrome browser. Google has released emergency updates to address a new zero-day vulnerability, tracked as CVE-2023-7024, in its web browser Chrome. The flaw has been addressed with the release of version 120.0.6099.129 for Mac,Linux and 120.0.6099.129/130 for Windows which will […]
newssecurityaffairs.comDec 20, 2023, 11:52 PM - Google addressed the sixth Chrome Zero-Day vulnerability in 2023Security Affairs
Google released security updates to address a new actively exploited zero-day vulnerability, tracked as CVE-2023-6345, in the Chrome browser. Google on Wednesday released security updates to address a new actively exploited zero-day, tracked as CVE-2023-6345, in the Chrome browser. The CVE-2023-5217 is a high-severity integer overflow in Skia. Skia is an open-source 2D graphics library […]
newssecurityaffairs.comNov 29, 2023, 7:04 PM - Google Patches Seventh Chrome Zero-Day of 2023SecurityWeek
The latest Chrome security update addresses the seventh exploited zero-day vulnerability documented in the browser in 2023.
newswww.securityweek.comNov 29, 2023, 12:18 PM Google has rushed to patch a new Chrome zero-day vulnerability, tracked as CVE-2023-5217 and exploited by a spyware vendor.
newswww.securityweek.comSep 28, 2023, 9:48 AM- GOOGLE FIXED THE FIFTH CHROME ZERO-DAY OF 2023Security Affairs
Google released security updates to address a new actively exploited zero-day vulnerability, tracked as CVE-2023-5217, in the Chrome browser. Google on Wednesday released security updates to address a new actively exploited zero-day flaw in the Chrome browser which is tracked as CVE-2023-5217. The CVE-2023-5217 is a high-severity heap buffer overflow that affects vp8 encoding in […]
newssecurityaffairs.comSep 28, 2023, 9:08 AM Google has released a Chrome 116 security update to patch CVE-2023-4863, the fourth Chrome zero-day vulnerability documented in 2023.
newswww.securityweek.comSep 12, 2023, 8:05 AM- GOOGLE FIXED THE FOURTH CHROME ZERO-DAY OF 2023Security Affairs
Google rolled out emergency security updates to address a new Chrome zero-day (CVE-2023-4863) actively exploited in the wild. Google rolled out emergency security updates to address a zero-day vulnerability that has been actively exploited in attacks in the wild since the start of the year. The vulnerability, tracked as CVE-2023-4863, is the fourth actively exploited […]
newssecurityaffairs.comSep 11, 2023, 9:13 PM - Google addressed 3 actively exploited flaws in AndroidSecurity Affairs
Google released July security updates for Android that addressed tens of vulnerabilities, including three actively exploited flaws. July security updates for Android addressed more than 40 vulnerabilities, including three flaws that were actively exploited in targeted attacks. “There are indications that the following may be under limited, targeted exploitation.” reads the security bulletin. The CVE-2023-26083 is […]
newssecurityaffairs.comJul 8, 2023, 5:34 PM Google’s July 2023 security updates for Android patches 43 vulnerabilities, including three exploited in the wild.
newswww.securityweek.comJul 6, 2023, 1:34 PMIn July’s update for the Android operating system (OS), Google has patched 43 vulnerabilities, three of which are actively exploited zero-day…
newswww.malwarebytes.comJul 5, 2023, 5:00 PM- Google fixed the third Chrome zero-day of 2023Security Affairs
Google released security updates to address a high-severity zero-day flaw in the Chrome web browser that it actively exploited in the wild. Google released security updates to address a high-severity vulnerability, tracked as CVE-2023-3079, in its Chrome web browser. The vulnerability is a type confusion issue that resides in the V8 JavaScript engine. The IT […]
newssecurityaffairs.comJun 6, 2023, 12:50 PM - CISA adds MinIO, PaperCut, and Chrome bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs
US Cybersecurity and Infrastructure Security Agency (CISA) added MinIO, PaperCut, and Chrome vulnerabilities to its Known Exploited Vulnerabilities catalog. U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the following three new issues to its Known Exploited Vulnerabilities Catalog: According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have […]
newssecurityaffairs.comApr 22, 2023, 6:28 PM - Update now, there’s a Chrome zero-day in the wildMalwarebytes Labs
Google has announced an important update for Chrome to help fend off a zero-day. The update fixes several issues, and readers…
newswww.malwarebytes.comApr 20, 2023, 5:00 PM Google rolled out emergency security patches to address another actively exploited high-severity zero-day flaw in the Chrome browser. Google rolled out emergency fixes to address another actively exploited high-severity zero-day flaw, tracked as CVE-2023-2136, in its Chrome web browser. The vulnerability is an Integer overflow in the Skia graphics library, the issue was reported by […]
newssecurityaffairs.comApr 19, 2023, 5:33 PMGoogle warns of another zero-day vulnerability in Chrome, only days after addressing a similar issue.
newswww.securityweek.comApr 19, 2023, 11:14 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-6345CVSS 9.6 · Critical
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a…
- CVE-2023-5849CVSS 8.8 · High
Integer overflow in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security sever…
- CVE-2021-21223CVSS 9.6 · Critical
Integer overflow in Mojo in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a cr…
- CVE-2020-15986CVSS 6.5 · Medium
Integer overflow in media in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-15975CVSS 8.8 · High
Integer overflow in SwiftShader in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-15974CVSS 8.8 · High
Integer overflow in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to bypass site isolation via a crafted HTML page.