Executive brief
An integer overflow vulnerability in the Skia graphics library allows a remote attacker who has compromised the renderer process to perform a sandbox escape via a malicious file. This vulnerability has been observed being exploited in the wild.
Affected products
- Google Skia
- Google Chrome prior to 119.0.6045.199
- Google ChromeOS
- Google Android
- Google Flutter
Timeline
- 2023-11-28: patched: Chrome stable channel update 119.0.6045.199 released.
- 2023-11-30: disclosed: CVE published.
- 2023-11-30: kev added: Added to CISA Known Exploited Vulnerabilities catalog.
- 2023-11-30: exploited: Reported as exploited in the wild.