CVE-2023-6345General(debian / chrome)

LOWCVSS 9.6 · CRITICALCISA KEV

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

1.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-12-21. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • debian_linux
  • edge_chromium
  • fedora

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • General: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
chromedebian_linuxedge_chromiumfedora

5 versions affected across 4 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-26: 203-26
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Zero Day Engineering@zerodayalpha
    General

    We're looking at Skia exploits – here is an insight blog from 2023 with some extra context: https://zerodayengineering.com/insights/chrome-skia-cve-2023-6345.html v8 zero to exploit: https://zerodayengineering.com/research/slides/VXCON2024_Workshop.pdf

    Post summary

    The post references a Skia-related CVE and links to a blog and slides, but offers no concrete PoC, exploit details, or patch information.

    00010101.4K
    10.6K followersView on X
  • Milos Constantin ♏(@Tinolle hachyderm.io )@Tinolle
    General

    Google Chrome Skia Vulnerability Analysis (CVE-2023-6345) https://zerodayengineering.com/insights/chrome-skia-cve-2023-6345.html

    Post summary

    The text contains only a title and a link to an analysis page for CVE-2023-6345, with no explicit details on PoC, exploitation, or patching.

    0000074
    3.2K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
OSdebiandebian_linux12.0--
OSfedoraprojectfedora37--
OSfedoraprojectfedora38--
OSfedoraprojectfedora39--
Appgooglechrome---
Appmicrosoftedge_chromium---

Explore more