ZeroHour

CVE-2023-6345

KEVmass1

Integer Overflow in Google Chrome's Skia Enables Sandbox Escape (Actively Exploited)

CISA: Google Skia Integer Overflow Vulnerability

CVSS 3.1
9.6 critical
EPSS
16%p97
Published
()
KEV added
AI analysis

CVE-2023-6345 is an integer overflow (CWE-190) in Skia, the 2D graphics rendering library used by Google Chrome and other Chromium-based browsers. It is triggered when a compromised renderer processes a malicious file, allowing a remote attacker who has already gained code execution in the renderer process to escape the Chrome sandbox and run code with broader privileges. Users of Google Chrome prior to 119.0.6045.199 are affected, as are Chromium-based derivatives including Microsoft Edge (Chromium) and Chromium packages shipped by Debian and Fedora. The flaw was rated High by Chromium, carries a CVSS 3.1 score of 9.6, and was added to CISA's Known Exploited Vulnerabilities catalog on 2023-11-30. Google has patched the bug in Chrome 119.0.6045.199, and news reporting confirms it was being actively exploited in the wild at the time of the fix.

What to do: Update Google Chrome to 119.0.6045.199 or later and restart the browser to fully apply the fix; on Debian and Fedora, apply the updated chromium packages from the distro repositories, and allow Microsoft's Chromium fix to flow into Edge before trusting affected builds. Verify browser versions (chrome://version or equivalent) across managed fleets, and note that because this is CISA KEV-listed (added 2023-11-30), US federal agencies must patch per vendor instructions or discontinue use by the required deadline.

Affected
Google Chromeprior to 119.0.6045.199
Google Chromium (Skia graphics library)Skia in Chromium prior to the fix released with Chrome 119.0.6045.199
Microsoft Edge (Chromium-based)
Debian Linux (chromium package)
Fedora Project Fedora (chromium package)
Estimated exposure
masshundreds of millions to billions of Chrome and Chromium-based browser installations — Chrome holds the largest desktop browser market share with a multi-billion-user install base, and Chromium derivatives (Microsoft Edge, Debian- and Fedora-packaged Chromium) inherit the vulnerable Skia code, so the vulnerable version…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

CISA Known Exploited Vulnerability
Affected
Google Chromium Skia
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
googledebianfedoraprojectmicrosoft
Products
chrome, debian linux, fedora, edge chromium
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news