ZeroHour

CVE-2023-2136

KEVmass1

Skia Integer Overflow Sandbox Escape in Google Chrome

CISA: Google Chrome Skia Integer Overflow Vulnerability

CVSS 3.1
9.6 critical
EPSS
6%p93
Published
()
KEV added
AI analysis

An integer overflow (CWE-190) in Skia, the 2D graphics library used by Chrome's renderer, can be triggered by a crafted HTML page whose content drives Skia processing past the limits of its integer math. A remote attacker who has already compromised the Chrome renderer process — for example through a separate renderer flaw or a malicious page — can leverage the overflow to escape Chrome's renderer sandbox and gain broader code execution on the host. All Google Chrome and Chromium users running versions prior to 112.0.5615.137 are affected, including Chromium packages shipped by Debian and Fedora. The flaw is rated Critical (CVSS 3.1: 9.6) and carries Chromium security severity High, with an EPSS probability of 5.7% (93rd percentile) of exploitation within 30 days. It was added to CISA's Known Exploited Vulnerability catalog on 2023-04-21, and news reports describe it as an actively exploited Chrome zero-day for which Google rushed out the 112.0.5615.137 patch.

What to do: Update Google Chrome to 112.0.5615.137 or later on all platforms, and install the corresponding Chromium security updates on Debian and Fedora systems. Because exploitation requires user interaction with a crafted page plus a pre-existing renderer compromise, prompt patching is the primary mitigation; verify via CISA KEV required actions that all managed browsers are updated and confirm Chrome versions in endpoint inventory.

Affected
Google Chromeall versions prior to 112.0.5615.137
Google ChromiumChromium builds with Skia code prior to the fix delivered in 112.0.5615.137
Debian Linux (chromium package)
Fedora Project Fedora (chromium package)
Estimated exposure
masson the order of billions of Chrome/Chromium users worldwide (~3+ billion installations; ~65% browser market share) — Chrome is the world's dominant desktop browser with roughly two-thirds market share and a user base Google has repeatedly stated exceeds three billion, so the pre-112.0.5615.137 population was in the billions, though most installations…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CISA Known Exploited Vulnerability
Affected
Google Chromium Skia
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googledebianfedoraproject
Products
chrome, debian linux, fedora
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news