CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2023-4860

CVSS 9.6v3.1pub. 2024-07-16upd. 2024-12-26

Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

🤖 AI Analysis
How it works

To exploit the vulnerability, an attacker must first compromise the browser's renderer process (e.g., through a separate vulnerability). Then, using an appropriately crafted HTML page, they can exploit the improper implementation in the Skia graphics library to escape from the sandbox mechanism. This action goes beyond the isolated browser environment and can lead to interactions with the user's operating system.

Impact

An attacker who has previously compromised the renderer process can escape the browser sandbox and gain access to operating system resources – potentially leading to data disclosure, modification, or system destabilization.

Mitigation & patch

Google Chrome should be updated to version 115.0.5790.98 or newer. The update is available through the browser's built-in update mechanism or on the manufacturer's website according to the references.

Who is affected

Google Chrome in versions earlier than 115.0.5790.98

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Google Chrome

    APP
    Google
    < 115.0.5790.98
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2024-7971CRITICAL9.6⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome/Edge) umożliwiający heap corruption

CVE-2024-5274CRITICAL9.6⚠ KEVPL ✓same product

Type Confusion w V8 (Google Chrome) — RCE przez spreparowaną stronę HTML

CVE-2024-4947CRITICAL9.6⚠ KEVPL ✓same product

Type Confusion w silniku V8 Chrome — zdalne wykonanie kodu (RCE)

CVE-2024-4671CRITICAL9.6⚠ KEVPL ✓same product

Use-after-free w Google Chrome Visuals umożliwiający ucieczkę z sandbox