CVE-2023-6345
published 2023-11-29CVE-2023-6345: Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a…
PriorityP187critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-12-21
Exploited in the wild
EPSS
19.63%
97.1th percentile
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 119.0.6045.199-1~deb11u1 | 119.0.6045.199-1~deb11u1 |
| chromium | chromium | >= 0 < 119.0.6045.199-1~deb12u1 | 119.0.6045.199-1~deb12u1 |
| chromium | chromium | >= 0 < 119.0.6045.199-1 | 119.0.6045.199-1 |
| chromium | chromium | >= 0 < 119.0.6045.199-1 | 119.0.6045.199-1 |
| debian | chromium | < chromium 119.0.6045.199-1~deb12u1 (bookworm) | chromium 119.0.6045.199-1~deb12u1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 119.0.6045.199 | 119.0.6045.199 | |
| chrome | >= 119.0.6045.199 < 119.0.6045.199 | 119.0.6045.199 | |
| chrome_chrome | — | — | |
| microsoft | edge_chromium | < 119.0.2151.97 | 119.0.2151.97 |
| msrc | microsoft_edge | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2023-6345 is confirmed exploited in the wild (ITW); prioritize detection of sandbox escape attempts originating from a compromised renderer process via malicious file processing in Chromium-based browsers ↗
- →The vulnerability resides in the Skia graphics library (integer overflow); monitor for anomalous renderer process behavior that may indicate sandbox escape attempts, particularly when processing files ↗
- →Affected surface is broad: Google Chrome, ChromeOS, Android, Flutter, and possibly other products embedding Skia or Chromium; expand detection scope beyond desktop Chrome ↗
- ·The vulnerability is in a common open-source component (Skia); vendors embedding Skia or Chromium may have independent patch timelines — check each vendor separately. ↗
- ·CISA KEV remediation due date was 2023-12-21; any asset still running a vulnerable version past this date should be treated as high-priority remediation. ↗
CVSS provenance
nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
osv9.6CRITICAL
vulncheck9.6CRITICAL
cisa9.6CRITICAL
vendor_debian9.6CRITICAL
vendor_msrc9.6CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2023-6345
vendor_chrome·2023-12-08·CVSS 9.6
CVE-2023-6345 [CRITICAL] Long Term Support Channel Update for ChromeOS: CVE-2023-6345
Long Term Support Channel Update for ChromeOS
CVE-2023-6345
CISA
Google Skia Integer Overflow Vulnerability
cisa·2023-11-30·CVSS 9.6
CVE-2023-6345 [CRITICAL] CWE-190 Google Skia Integer Overflow Vulnerability
Vulnerability: Google Skia Integer Overflow Vulnerability
Affected: Google Chromium Skia
Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a malicious file. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://chromereleases.googleblog.com/2023/11/st
Chrome
Stable Channel Update for Desktop: CVE-2023-6350
vendor_chrome·2023-11-28·CVSS 9.6
CVE-2023-6350 [HIGH] Stable Channel Update for Desktop: CVE-2023-6350
Stable Channel Update for Desktop
CVE-2023-6350: Out of bounds memory access in libavif. Reported by Fudan University on 2023-11-13 [$7000][ 1501770 ] High CVE-2023-6351: Use after free in libavif
Reported by Fudan University on 2023-11-13 [N/A][ 1505053 ] High CVE-2023-6345: Integer overflow in Skia
Severity: high
Microsoft
Chromium: CVE-2023-6345 Integer overflow in Skia
vendor_msrc·2023-11-14·CVSS 9.6
CVE-2023-6345 [CRITICAL] Chromium: CVE-2023-6345 Integer overflow in Skia
Chromium: CVE-2023-6345 Integer overflow in Skia
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2023-6345 exists in the wild.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the windo
Debian
CVE-2023-6345: chromium - Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remo...
vendor_debian·2023·CVSS 9.6
CVE-2023-6345 [CRITICAL] CVE-2023-6345: chromium - Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remo...
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 119.0.6045.199-1~deb12u1)
bullseye: resolved (fixed in 119.0.6045.199-1~deb11u1)
forky: resolved (fixed in 119.0.6045.199-1)
sid: resolved (fixed in 119.0.6045.199-1)
trixie: resolved (fixed in 119.0.6045.199-1)
OSV
CVE-2023-6345: Integer overflow in Skia in Google Chrome prior to 119
osv·2023-11-29·CVSS 9.6
CVE-2023-6345 [CRITICAL] CVE-2023-6345: Integer overflow in Skia in Google Chrome prior to 119
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
GHSA
GHSA-xm5p-7w7v-qqr5: Integer overflow in Skia in Google Chrome prior to 119
ghsa_unreviewed·2023-11-29
CVE-2023-6345 [CRITICAL] CWE-190 GHSA-xm5p-7w7v-qqr5: Integer overflow in Skia in Google Chrome prior to 119
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
VulnCheck
Google Skia Integer Overflow Vulnerability
vulncheck·2023·CVSS 9.6
CVE-2023-6345 [CRITICAL] CWE-190 Google Skia Integer Overflow Vulnerability
Google Skia Integer Overflow Vulnerability
Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a malicious file. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.
Affected: Google Chromium Skia
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://chromereleases.googleblog.com/2023/11/stable-channel-update-for-desktop_28.html; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https:/
Project0
Project Zero RCA: CVE-2023-6345: Integer overflow in Skia MeshOp::onCombineIfPossible
project_zero·CVSS 9.6
CVE-2023-6345 [CRITICAL] Project Zero RCA: CVE-2023-6345: Integer overflow in Skia MeshOp::onCombineIfPossible
# CVE-2023-6345: Integer overflow in Skia MeshOp::onCombineIfPossible
*Benoît Sevens and Clement Lecigne*
## The Basics
**Disclosure or Patch Date:** November 28, 2023
**Product:** Google Chrome
**Advisory:** https://chromereleases.googleblog.com/2023/11/stable-channel-update-for-desktop_28.html
**Affected Versions:** Versions older than 119.0.6045.199
**First Patched Version:** 119.0.6045.199
**Issue/Bug Report:** https://crbug.com/1505053
**Patch CL:** https://skia.googlesource.com/skia/+/6169a1fabae1743709bc9641ad43fcbb6a4f62e1
**Bug-Introducing CL:** https://skia.googlesource.com/skia/+/8a85ab0d96a1128c64fa21133518e835506b3895
**Reporter(s):** Benoît Sevens and Clément Lecigne of Google's Threat Analysis Group
## The Code
**Proof-of-concept:**
Compile Skia with [ASAN](http
No detection rules found.
No public exploits indexed.
Mandiant
Look What You Made Us Patch: 2025 Zero-Days in Review
blogs_mandiant·2026-03-05
Look What You Made Us Patch: 2025 Zero-Days in Review
Threat Intelligence
# Look What You Made Us Patch: 2025 Zero-Days in Review
March 5, 2026
##### Google Threat Intelligence Group
##### Google Threat Intelligence
Visibility and context on the threats that matter most.
Contact Us & Get a Demo
Written by: Casey Charrier, James Sadowski, Zander Work, Clement Lecigne, Benoît Sevens, Fred Plan
### Executive Summary
Google Threat Intelligence Group (GTIG) tracked 90 zero-day vulnerabilities exploited in-the-wild in 2025. Although that volume of zero-days is lower than the record high observed in 2023 (100), it is higher than 2024’s count (78) and remained within the 60–100 range established over the previous four years, indicating a trend toward stabilization at these levels.
In 2025, we continued to observe the structural shift, first
Mandiant
Look What You Made Us Patch: 2025 Zero-Days in Review
blogs_mandiant·2026-03-05
Look What You Made Us Patch: 2025 Zero-Days in Review
## Look What You Made Us Patch: 2025 Zero-Days in Review
## Google Threat Intelligence Group
## Google Threat Intelligence
Visibility and context on the threats that matter most.
Written by: Casey Charrier, James Sadowski, Zander Work, Clement Lecigne, Benoît Sevens, Fred Plan
## Executive Summary
Google Threat Intelligence Group (GTIG) tracked 90 zero-day vulnerabilities exploited in-the-wild in 2025. Although that volume of zero-days is lower than the record high observed in 2023 (100), it is higher than 2024’s count (78) and remained within the 60–100 range established over the previous four years, indicating a trend toward stabilization at these levels.
In 2025, we continued to observe the structural shift, first identified in 2024, toward increased enterprise exploitation. Both
Bleepingcomputer
Google fixes first actively exploited Chrome zero-day of 2024
blogs_bleepingcomputer·2024-01-16·CVSS 8.8
CVE-2024-0519 [HIGH] Google fixes first actively exploited Chrome zero-day of 2024
## Google fixes first actively exploited Chrome zero-day of 2024
## Sergiu Gatlan
Although Google says the security update could take days or weeks to reach all impacted users, it was available immediately when BleepingComputer checked for updates today.
Those who prefer not to update their web browser manually can rely on Chrome to automatically check for new updates and install them after the next launch.
The high-severity zero-day vulnerability ( CVE-2024-0519 ) is due to a high-severity out-of-bounds memory access weakness in the Chrome V8 JavaScript engine, which remote attackers can exploit via a crafted HTML page to gain access to data beyond the memory buffer through heap corruption, providing them access to sensitive information or triggering a crash.
"The expected sentinel
Bleepingcomputer
Google fixes 8th Chrome zero-day exploited in attacks this year
blogs_bleepingcomputer·2023-12-20·CVSS 8.8
[HIGH] Google fixes 8th Chrome zero-day exploited in attacks this year
## Google fixes 8th Chrome zero-day exploited in attacks this year
## Sergiu Gatlan
The bug was discovered and reported by Clément Lecigne and Vlad Stolyarov of Google's Threat Analysis Group (TAG), a collective of security experts whose primary goal is to defend Google customers from state-sponsored attacks.
Google's Threat Analysis Group (TAG) frequently discovers zero-day bugs exploited by government-sponsored threat actors in targeted attacks aiming to deploy spyware on the devices of high-risk individuals, including opposition politicians, dissidents, and journalists.
Even though the security update could take days or weeks to reach all users, according to Google, it was available immediately when BleepingComputer checked for updates earlier today.
Individuals who prefer not t
Checkpoint
4th December – Threat Intelligence Report
blogs_checkpoint·2023-12-04·CVSS 7.5
CVE-2023-4966 [HIGH] 4th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 4th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 4th December, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Check Point Research provides highlights about Cyber Av3ngers group activity, which has taken responsibility on defacing workstations at Pennsylvania’s Aliquippa municipal water authority. Following the attack, CISA has published an advisory about this hacktivists group which is affiliated to Iranian Revolutionary Guard C
Bleepingcomputer
Google Chrome emergency update fixes 7th zero-day exploited in 2023
blogs_bleepingcomputer·2023-11-28·CVSS 9.6
[CRITICAL] Google Chrome emergency update fixes 7th zero-day exploited in 2023
## Google Chrome emergency update fixes 7th zero-day exploited in 2023
## Sergiu Gatlan
The vulnerability has been addressed in the Stable Desktop channel, with patched versions rolling out globally to Windows users (119.0.6045.199/.200) and Mac and Linux users (119.0.6045.199).
Although the advisory notes that the security update may take days or weeks to reach the entire user base, it was available immediately when BleepingComputer checked for updates earlier today.
Users who don't want to update manually can rely on the web browser to check for new updates automatically and install them after the next launch.
## Likely exploited in spyware attacks
This high-severity zero-day vulnerability stems from an integer overflow weakness within the Skia open-source 2D graphics library, pos
Greynoiseio
Storm Watch
blogs_greynoiseio
Storm Watch
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
https://chromereleases.googleblog.com/2023/11/stable-channel-update-for-desktop_28.htmlhttps://crbug.com/1505053https://lists.fedoraproject.org/archives/list/[email protected]/message/6T7ABNYMOI4ZHVCSPCNP7HQTOLGF53A2/https://lists.fedoraproject.org/archives/list/[email protected]/message/C7XQNYZZA3X2LBJF57ZHKXWOMJKNLZYR/https://lists.fedoraproject.org/archives/list/[email protected]/message/UJROPNKWW65R34J4IYGTJ7A3OBPUL4IQ/https://security.gentoo.org/glsa/202401-34https://www.debian.org/security/2023/dsa-5569https://chromereleases.googleblog.com/2023/11/stable-channel-update-for-desktop_28.htmlhttps://crbug.com/1505053https://lists.fedoraproject.org/archives/list/[email protected]/message/6T7ABNYMOI4ZHVCSPCNP7HQTOLGF53A2/https://lists.fedoraproject.org/archives/list/[email protected]/message/C7XQNYZZA3X2LBJF57ZHKXWOMJKNLZYR/https://lists.fedoraproject.org/archives/list/[email protected]/message/UJROPNKWW65R34J4IYGTJ7A3OBPUL4IQ/https://security.gentoo.org/glsa/202401-34https://www.debian.org/security/2023/dsa-5569https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-6345
2023-11-29
Published
2023-11-30
Added to CISA KEV
Exploited in the wild