Record summary

CVE-2023-6345 has a selected CVSS score of 9.6 (critical). CISA lists CVE-2023-6345 in KEV.

Description

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Nov 30, 2023 · CISA
VulnCheck KEV
Listed · Sep 28, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 1, 2023 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List119.0.6045.199 to < 119.0.6045.199affected
CISAVersion data not supplied

References

9