Google addressed another zero-day vulnerability tracked as CVE-2023-2136, for the Chrome web browser in the new version 112.0.5615.137, which fixes a total of 8 vulnerabilities. The stable release is available only for Windows and Mac users, while the Linux version will be rolled out soon. Also, Google stated that they are aware of the CVE-2023-2136 vulnerability being exploited in the 2023 attacks. The zero-day vulnerability, assigned with the CVE-2023-2136, is described as a high-severity integer overflow flaw discovered in Skia, a C++-based open-source, multi-platform 2D graphics library that is owned by Google. Skia is considered an essential component of Chrome's rendering pipeline since it gives the web browser a set of APIs for producing graphics, text, shapes, pictures, and animations. The integer overflow in Skia causes improper rendering, memory corruption, and arbitrary code execution, which allows unauthorized access to the system. Furthermore, as standard practices of fixing actively exploited flaws in Chrome, Google withheld some information about how CVE-2023-2136 was used in attacks and restricted access to the bug's details and related links until the majority of users received the fix. Google will also keep the restrictions if the flaw is found in the third-party library which is used by other projects but hasn't yet been fixed.
Cybersecurity researchers have uncovered another evolution of the ongoing supply chain attack linked to the Mini Shai Hulud, Miasma, and Hades malware family, targeting both the np...
Amazon has addressed a high-severity security vulnerability, tracked as CVE-2026-12957, affecting Amazon Q Developer IDE plugins. The flaw could allow a malicious Git repository to...
?An active phishing campaign has targeted hotels and hospitality organizations across Europe and Asia since April 2026. Attackers send emails impersonating "Booking Manager (vi...