chromereleases.googleblog.com
https://chromereleases.googleblog.com/2023/11/stable-channel-update-for-desktop_28.html CVE-2023-6345
CRITICALCISA KEV
Google Skia Integer Overflow Vulnerability
Record summary
CVE-2023-6345 has a selected CVSS score of 9.6 (critical). CISA lists CVE-2023-6345 in KEV.
Description
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Nov 30, 2023 · CISA
- VulnCheck KEV
- Listed · Sep 28, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationActive
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 1, 2023 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
ChromeBrowse Google / Chrome | CVE List | 119.0.6045.199 to < 119.0.6045.199 | affected |
Chromium SkiaBrowse Google / Chromium Skia | CISA | Version data not supplied | |
References
9crbug.com
https://crbug.com/1505053 lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6T7ABNYMOI4ZHVCSPCNP7HQTOLGF53A2 lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C7XQNYZZA3X2LBJF57ZHKXWOMJKNLZYR lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UJROPNKWW65R34J4IYGTJ7A3OBPUL4IQ nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-6345 security.gentoo.org
https://security.gentoo.org/glsa/202401-34 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-6345 debian.org
https://www.debian.org/security/2023/dsa-5569