⚠ Actively exploited
Added to CISA KEV on 2023-11-30. Federal agencies required to patch by 2023-12-21. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..

CVE-2023-6345Integer Overflow or Wraparound in Google Chrome

Severity
9.6CRITICALNVD
EPSS
0.7%
top 27.48%
CISA KEV
KEV
Added 2023-11-30
Due 2023-12-21
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedNov 29
KEV addedNov 30
Latest updateDec 8
KEV dueDec 21
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 2.8 | Impact: 6.0

Affected Packages4 packages

CVEListV5google/chrome119.0.6045.199119.0.6045.199
NVDgoogle/chrome< 119.0.6045.199
NVDmicrosoft/edge_chromium< 119.0.2151.97
Debianchromium/chromium< 119.0.6045.199-1~deb11u1+3

Also affects: Debian Linux 11.0, 12.0, Fedora 37, 38, 39

🔴Vulnerability Details

5
CVEList
CVE-2023-6345: Integer overflow in Skia in Google Chrome prior to 1192023-11-29
OSV
CVE-2023-6345: Integer overflow in Skia in Google Chrome prior to 1192023-11-29
GHSA
GHSA-xm5p-7w7v-qqr5: Integer overflow in Skia in Google Chrome prior to 1192023-11-29
VulnCheck
Google Skia Integer Overflow Vulnerability2023
Project0
Project Zero RCA: CVE-2023-6345: Integer overflow in Skia MeshOp::onCombineIfPossible

📋Vendor Advisories

5
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2023-63452023-12-08
CISA
Google Skia Integer Overflow Vulnerability2023-11-30
Chrome
Stable Channel Update for Desktop: CVE-2023-63502023-11-28
Microsoft
Chromium: CVE-2023-6345 Integer overflow in Skia2023-11-14
Debian
CVE-2023-6345: chromium - Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remo...2023
CVE-2023-6345 — Integer Overflow or Wraparound | cvebase