Junglewise Threat Intelligence

CVE-2023-6345: Google Skia Integer Overflow Vulnerability

CVE-2023-6345 · Severity: critical · CVSS 9.6 · Exploited in the wild · Published 2023-11-30

Technologies: Google Chrome, Google Android, Google ChromeOS, Google Skia. Vendors: Google.

Executive brief

An integer overflow vulnerability in the Skia graphics library allows a remote attacker who has compromised the renderer process to perform a sandbox escape via a malicious file. This vulnerability has been observed being exploited in the wild.

Affected products

  • Google Skia
  • Google Chrome prior to 119.0.6045.199
  • Google ChromeOS
  • Google Android
  • Google Flutter

Timeline

  • 2023-11-28: patched: Chrome stable channel update 119.0.6045.199 released.
  • 2023-11-30: disclosed: CVE published.
  • 2023-11-30: kev added: Added to CISA Known Exploited Vulnerabilities catalog.
  • 2023-11-30: exploited: Reported as exploited in the wild.

Related threats