Advertisement
Top
image credit: Unsplash

Google Chrome Hit by Second Zero-Day Attack – Urgent Patch Update Released

April 19, 2023

Google on Tuesday rolled out emergency fixes to address another actively exploited high-severity zero-day flaw in its Chrome web browser.

The flaw, tracked as CVE-2023-2136, is described as a case of integer overflow in Skia, an open source 2D graphics library. Clément Lecigne of Google’s Threat Analysis Group (TAG) has been credited with discovering and reporting the flaw on April 12, 2023.

“Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page,” according to the NIST’s National Vulnerability Database (NVD).

Read More on The Hacker News