CVE-2023-6345
KEVmass1Integer Overflow in Google Chrome's Skia Enables Sandbox Escape (Actively Exploited)
CISA: Google Skia Integer Overflow Vulnerability
CVE-2023-6345 is an integer overflow (CWE-190) in Skia, the 2D graphics rendering library used by Google Chrome and other Chromium-based browsers. It is triggered when a compromised renderer processes a malicious file, allowing a remote attacker who has already gained code execution in the renderer process to escape the Chrome sandbox and run code with broader privileges. Users of Google Chrome prior to 119.0.6045.199 are affected, as are Chromium-based derivatives including Microsoft Edge (Chromium) and Chromium packages shipped by Debian and Fedora. The flaw was rated High by Chromium, carries a CVSS 3.1 score of 9.6, and was added to CISA's Known Exploited Vulnerabilities catalog on 2023-11-30. Google has patched the bug in Chrome 119.0.6045.199, and news reporting confirms it was being actively exploited in the wild at the time of the fix.
What to do: Update Google Chrome to 119.0.6045.199 or later and restart the browser to fully apply the fix; on Debian and Fedora, apply the updated chromium packages from the distro repositories, and allow Microsoft's Chromium fix to flow into Edge before trusting affected builds. Verify browser versions (chrome://version or equivalent) across managed fleets, and note that because this is CISA KEV-listed (added 2023-11-30), US federal agencies must patch per vendor instructions or discontinue use by the required deadline.
| Google Chrome | prior to 119.0.6045.199 |
| Google Chromium (Skia graphics library) | Skia in Chromium prior to the fix released with Chrome 119.0.6045.199 |
| Microsoft Edge (Chromium-based) | — |
| Debian Linux (chromium package) | — |
| Fedora Project Fedora (chromium package) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
- Affected
- Google Chromium Skia
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- googledebianfedoraprojectmicrosoft
- Products
- chrome, debian linux, fedora, edge chromium
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H