NA

CVE-2023-6345

Published: 29/11/2023 Updated: 31/01/2024
CVSS v3 Base Score: 9.6 | Impact Score: 6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Integer overflow in Skia in Google Chrome before 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

debian debian linux 11.0

debian debian linux 12.0

fedoraproject fedora 37

fedoraproject fedora 38

fedoraproject fedora 39

microsoft edge chromium

Vendor Advisories

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure For the oldstable distribution (bullseye), these problems have been fixed in version 11906045199-1~deb11u1 For the stable distribution (bookworm), these problems have been fixed in version 119 ...
The Stable channel has been updated to 11906045199 for Mac and Linux and 11906045199/200 for Windows, which will roll out over the coming days/weeks A full list of changes in this build is available in the log Security Fixes and RewardsNote: Access to bug details and links may be kept restricted until a majority of users are ...
 LTS-114 is being updated in the LTS channel to 11405735343 (Platform Version: 15437810) for most ChromeOS devices Want to know more about Long Term Support? Click hereThis update contains multiple Security fixes, including:1505053 High  CVE-2023-6345 Integer overflow in Skia1497997 High CVE ...

Recent Articles

Uh-oh, update Google Chrome – exploit already out there for one of these 6 security holes
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Plus: 3 critical CVEs in Zyxel NAS devices

Google has rolled out six Chrome security fixes including one emergency patch for a bug for which exploit code is already out there. You're encouraged to thus grab the latest updates for the browser. This latest zero-day flaw, tracked as CVE-2023-6345, is a high-severity integer overflow vulnerability in Skia, a popular graphics library used by Chrome. To exploit this bug, an attacker would need to have already compromised the renderer process, at which point they may be able to perform a sandbo...

Apple slaps patch on WebKit holes in iPhones and Macs amid fears of active attacks
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Two CVEs can be abused to steal sensitive info or execute code

Apple has issued emergency fixes to plug security flaws in iPhones, iPads, and Macs that may already be under attack. The software updates for iOS, iPadOS, macOS Sonoma, and Safari web browser address two bugs: an out-of-bounds read flaw tracked as CVE-2023-42916, and a memory corruption vulnerability tracked as CVE-2023-42917.  Both are in the WebKit web browser engine – the heart of Safari, as found on iThings and Macs – and can be abused to access sensitive information (CVE-2023-4291...