CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2023-6345

CVSS 9.6v3.1pub. 2023-11-29upd. 2025-10-24

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

🤖 AI Analysis
How it works

An integer overflow error in the Skia component (2D graphics library used by Chrome) allows an attacker who has gained control of the browser's renderer process to escape sandbox isolation. The attack is initiated by tricking a user into opening a malicious file, which triggers an integer overflow during graphics data processing. Successful overflow can lead to code execution outside the protected renderer environment.

Impact

An attacker who has previously compromised a renderer process can potentially escape the Chrome sandbox and gain fuller access to the operating system, including code execution with higher privileges and compromise of confidentiality, integrity, and availability of data.

Mitigation & patch

Google Chrome must be updated immediately to version 119.0.6045.199 or later. Users of Debian Linux and Fedora distributions should apply patches available in repositories according to vendor references. Due to active exploitation of the vulnerability, the update should be performed immediately.

Who is affected

Google Chrome in versions earlier than 119.0.6045.199, as well as Chrome/Chromium packages for Debian Linux and Fedora (indicated distribution versions in vendor references)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Debian

    OS
    Debian
    11.012.0
  • Fedora Project Fedora

    OS
    Fedoraproject
    373839
  • Google Chrome

    APP
    Google
    < 119.0.6045.199
  • Microsoft Edge

    APP
    Microsoft
    < 119.0.2151.97

CISA KEV — detailsi

Vendori
Google
Producti
Chromium Skia
Added to KEVi
November 30, 2023
Remediation deadline (US Federal)i
December 21, 2023(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a malicious file. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 21 grudnia 2023
CWE
References

Related vulnerabilities

CVE-2026-24061CRITICAL9.8⚠ KEVPL ✓same product

GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)

CVE-2025-49113CRITICAL9.9⚠ KEVPL ✓same product

RCE przez deserializację PHP w Roundcube Webmail (parametr _from)

CVE-2025-32433CRITICAL10.0⚠ KEVPL ✓same product

Erlang/OTP SSH — nieuwierzytelniony RCE (CVSS 10.0)