CVE-2023-2136: Integer overflow in Skia
Chromium: CVE-2023-2136 Integer overflow in Skia
Other sources
Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.
— CISA
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2023-2136 exists in the wild.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 116.0.5845.180-1~deb11u1Fixed in 119.0.6045.123-1~deb11u1Fixed in 116.0.5845.180-1~deb12u1Fixed in 119.0.6045.123-1~deb12u1Fixed in 119.0.6045.105-1Fixed in 119.0.6045.123-1 - Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 112.0.5615.137 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 116.0.5845.180-1~deb11u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 119.0.6045.123-1~deb11u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 116.0.5845.180-1~deb12u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 119.0.6045.123-1~deb12u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 119.0.6045.105-1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 119.0.6045.123-1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for the Google Chrome Skia Integer Overflow vulnerability?
The vulnerability ID for the Google Chrome Skia Integer Overflow vulnerability is CVE-2023-2136.
What is the severity of CVE-2023-2136?
The severity of CVE-2023-2136 is critical with a severity value of 9.
Which software products are affected by CVE-2023-2136?
The affected software products include Google Chrome, Google Android, Microsoft Edge (Chromium-based), Microsoft Edge, Debian Debian Linux, and Fedoraproject Fedora.
Where can I find more information about CVE-2023-2136?
You can find more information about CVE-2023-2136 at the following references: - [Microsoft Security Response Center](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-2136) - [Google Chrome Releases](https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_18.html) - [Android Googlesource](https://android.googlesource.com/platform/external/skia/+/cfaa1ca1ceec8ec46ffbc89f707d280007a52c83)
How do I fix the Google Chrome Skia Integer Overflow vulnerability?
To fix the Google Chrome Skia Integer Overflow vulnerability, update your software to the latest version available from the respective vendors' websites.