ZeroHour
The Recordpublished ()ingested

Latest severe Chrome bug prompts CISA warning

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-6345

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-6345
Integer Overflow in Google Chrome's Skia Enables Sandbox Escape (Actively Exploited)

CVE-2023-6345 is an integer overflow (CWE-190) in Skia, the 2D graphics rendering library used by Google Chrome and other Chromium-based browsers. It is triggered when a compromised renderer processes a malicious file, allowing a remote attacker who has already gained code execution in the renderer process to escape the Chrome sandbox and run code with broader privileges. Users of Google Chrome prior to 119.0.6045.199 are affected, as are Chromium-based derivatives including Microsoft Edge (Chromium) and Chromium packages shipped by Debian and Fedora. The flaw was rated High by Chromium, carries a CVSS 3.1 score of 9.6, and was added to CISA's Known Exploited Vulnerabilities catalog on 2023-11-30. Google has patched the bug in Chrome 119.0.6045.199, and news reporting confirms it was being actively exploited in the wild at the time of the fix.

Do: Update Google Chrome to 119.0.6045.199 or later and restart the browser to fully apply the fix; on Debian and Fedora, apply the updated chromium packages from the distro repositories, and allow Microsoft's Chromium fix to flow into Edge before trusting affected builds. Verify browser versions (chrome://version or equivalent) across managed fleets, and note that because this is CISA KEV-listed (added 2023-11-30), US federal agencies must patch per vendor instructions or discontinue use by the required deadline.

9.616% KEV
  • Google Chrome prior to 119.0.6045.199
  • Google Chromium (Skia graphics library) Skia in Chromium prior to the fix released with Chrome 119.0.6045.199
  • Microsoft Edge (Chromium-based)
  • +2 more
masshundreds of millions to billions of Chrome and Chromium-based browser installations
Full article427 words · extracted from therecord.media · click to collapse

A severe vulnerability that led Google to issue an emergency update of the Chrome browser has been exploited on the open internet, the Cybersecurity and Infrastructure Security Agency (CISA) confirmed Thursday.

The bug, which affects 2D graphics-rendering code known as Skia, has been added to the agency’s Known Exploited Vulnerabilities (KEV) catalog. Google released a security fix on Tuesday for the flow, tracked as CVE-2023-6345.

The company said at the time that it was “aware that an exploit for CVE-2023-6345 exists in the wild,” but did not offer more information. Inclusion on the KEV list indicates that CISA agreed with that assessment. Federal civilian agencies have until December 21 to address the bug on any affected systems.

The bug was originally reported on November 24 by researchers at Google’s own Threat Analysis Group, the company said. The Skia code library is “sponsored and managed” by Google, but it is an open source project available for other developers.

Chrome vulnerabilities occasionally rise to a level of severity that prompts Google to issue a patch as soon as one is ready, instead of waiting for the next regular update cycle. Earlier this fall, for example, the company released fixes specifically for a bug in an open source tool known as libvpx, used in video encoding.

Experts are urging organizations to ensure that users have the latest version not just of Chrome, but other browsers that are based on its core code, including Microsoft Edge.

“Despite all the care taken by Google engineers, we continue to see a steady stream of security issues that are exploitable,” including zero-days that are actually used by malicious hackers, said Lionel Litty, chief security architect at Menlo Security.

As software like Chrome only becomes more complex, the opportunity for bugs to arise also expands, experts say.

Chrome’s wide use also makes it attractive to “sophisticated attackers, including those backed by state sponsors,” noted Saeed Abbasi, manager of vulnerability and threat research at Qualys.

CISA also added a recently reported bug in the open source ownCloud software to the KEV list.

Jonathan Greig contributed to this story.

No previous article

No new articles

Joe Warminsky

has been the news editor for Recorded Future News since 2022. He has three decades of experience as an editor and writer in the Washington, D.C., area. He previously he helped lead CyberScoop for more than five years. Prior to that, he was a digital editor at WAMU 88.5, the NPR affiliate in Washington, and he spent more than a decade editing coverage of Congress for CQ Roll Call.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/latest-severe-chrome-bug-prompts-cisa-warning