CRITICAL

CVE-2023-6345

Google Chrome 2023-11-29 CVSS v3.1
CVSS
9.6
KEV

Description

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

Summary dbcve.org

An integer overflow vulnerability exists in Skia, Google's 2D graphics rendering library used by Chrome. The flaw can be triggered when a compromised renderer process processes a malicious file, potentially allowing the attacker to escape Chrome's sandbox isolation. This is a high-severity issue as it provides a pathway to break out of the sandbox defense-in-depth layer.

Mitigation

Update Google Chrome to version 119.0.6045.199 or later. In enterprise environments, ensure patch management processes deploy browser updates promptly, as this vulnerability requires only that a user open a malicious file.

Weakness (CWE)

CWE-190 Integer Overflow

EPSS Score

16.47%
Probability of exploitation in next 30 days
96.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE