{"cveID":"CVE-2023-2136","vendorProject":"Google","product":"Chromium Skia","vulnerabilityName":"Google Chrome Skia Integer Overflow Vulnerability","dateAdded":"2023-04-21","shortDescription":"Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2023-05-12","knownRansomwareCampaignUse":"Unknown","notes":"https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_18.html;  https://nvd.nist.gov/vuln/detail/CVE-2023-2136","cwes":["CWE-190"],"year":2023,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2023-2136","technique":"T1204.001","technique_name_at_mapping":"Malicious Link","mapping_type":"exploitation_technique","capability_group":"int_overflow","comments":"This integer overflow vulnerability is exploited by a remote attacker who has already compromised the renderer process of Google Chrome. Exploiting this vulnerability might lead to incorrect rendering, memory corruption, and arbitrary code execution that could grant the adversary unauthorized access to the system. \n\nExploitation in the wild techniques have not been publicly released to reduce further abuse. ","references":["https://www.bleepingcomputer.com/news/security/google-patches-another-actively-exploited-chrome-zero-day/","https://thehackernews.com/2023/04/google-chrome-hit-by-second-zero-day.html"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1204.001","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Malicious Link","name_at_mapping":"Malicious Link","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":4,"has_detection_strategy":true}],"mapping_types":["exploitation_technique"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}