CVE-2023-6345
Description
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Summary dbcve.org
An integer overflow vulnerability exists in Skia, Google's 2D graphics rendering library used by Chrome. The flaw can be triggered when a compromised renderer process processes a malicious file, potentially allowing the attacker to escape Chrome's sandbox isolation. This is a high-severity issue as it provides a pathway to break out of the sandbox defense-in-depth layer.
Mitigation
Update Google Chrome to version 119.0.6045.199 or later. In enterprise environments, ensure patch management processes deploy browser updates promptly, as this vulnerability requires only that a user open a malicious file.