VDB
CVE-2023-2136
CVE-2023-2136
PUBLISHED
KEV
Es existieren mehrere Schwachstellen in Google Chrome und Microsoft Edge. Betroffen sind die Komponenten Service Worker API, DevTools, Skia und Sqlite aufgrund von Out-of-Bounds-Speicherzugriffen, Überläufen und einem Use-after-free-Fehler. Ein entfernter, anonymer Angreifer kann diese Schwachstellen zur Ausführung von beliebigem Code ausnutzen. Eine erfolgreiche Ausnutzung erfordert eine Benutzerinteraktion.
EPSS 0.44% · 63.4th percentile
Risk Scores
EPSS Score
0.44%
63.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samsung | Samsung Android | |
| Samsung | Samsung Android 12l | |
| Samsung | Samsung Android 11 | |
| Google Android 13 | ||
| Microsoft | Microsoft Edge < 112.0.1722.58 | |
| Google Android 12L | ||
| Gentoo | Gentoo Linux | |
| Microsoft | Microsoft Edge < 109.0.1518.100 | |
| SUSE | SUSE Linux | |
| Google Android 12 | ||
| Debian | Debian Linux | |
| Samsung | Samsung Android 12 | |
| Google Android 11 | ||
| Samsung | Samsung Android 13 | |
| Ubuntu | Ubuntu Linux | |
| Fedora | Fedora Linux |
Exploit Intelligence
- Integer overflow in Skia (Google Chrome) (gpz)
- Integer overflow in Skia (Google Chrome) (gpz)
- Integer overflow in Skia (Google Chrome) (gpz)
- Integer overflow in Skia (Google Chrome) (gpz)
- Integer overflow in Skia (Google Chrome) (gpz)
- Integer overflow in Skia (Google Chrome) (gpz)
- Integer overflow in Skia (Google Chrome) (gpz)
- rules.yar (github-yara)
- rules.yar (github-yara)
- rules.yar (github-yara)
…and 42 more exploits
Timeline
- Apr 18, 2023 PoC Published
- Apr 18, 2023 CVE Published
- Apr 19, 2023 EPSS Score
- Apr 21, 2023 CISA KEV Added
- May 26, 2023 EPSS Score
- Jul 3, 2023 EPSS Score
- Aug 9, 2023 EPSS Score
- Sep 16, 2023 EPSS Score
- Nov 30, 2023 EPSS Score
- Nov 30, 2023 CVE Updated
- Jan 6, 2024 EPSS Score
- Feb 13, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1000.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1000 advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-November/017262.html advisory
- https://security.gentoo.org/glsa/202309-17 advisory
- https://docs.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security advisory
- https://learn.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security#april-21-2023 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-911c060ded advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-91a369658f advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-2b6ba1c253 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-221f366aca advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-fa739b5753 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-30f3deb00a advisory
- https://www.debian.org/security/2023/dsa-5393 advisory
- https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-8cc9731416 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-c1741c9724 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-df075a7f85 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-9631f50abc advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-c126e4af73 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-fc1538262d advisory
…and 11 more