CVE-2024-8193 is a heap-based buffer overflow in Skia affecting Google Chrome versions before 128.0.6613.113. A remote attacker who has already compromised the Chrome renderer process can use a crafted HTML page to potentially exploit the resulting heap corruption.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (PoC) exploit for a vulnerability in Google Chrome (fixed in version 128) that leads to a GPU process crash via an out-of-bounds write. The exploit consists of four files: - `chromium.diff`: A patch to Chromium's source code (specifically, gpu/command_buffer/client/raster_implementation.cc) that adds code to process a specially crafted Skia picture and trigger the vulnerability. - `genskpic.py`: A Python script that generates a malicious Skia picture file (`pic.skp`) and a corresponding C++ header file (`drawable_picture.skp.hh`). The header is used in the patched Chromium build. - `index.html`: A minimal HTML file with JavaScript that draws on a canvas, triggering the rendering path that leads to the vulnerability when loaded in the patched browser. - `README.md`: Instructions for applying the patch, generating the payload, building Chromium, and triggering the crash. The exploit demonstrates the vulnerability by causing a crash in the GPU process when the crafted HTML page is loaded in the patched browser. There are no network endpoints or remote exploitation; the attack vector is local, requiring a custom build of Chromium. The exploit is a PoC and does not provide code execution, only a crash (OOB write) to demonstrate the bug.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability addressed by the Miracle Linux 9 WebKitGTK3 package update.
Heap-buffer-overflow vulnerability in Skia included in WebKitGTK.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.