Google Skia Integer Overflow Vulnerability
Summary
| CVE | CVE-2023-6345 |
|---|---|
| State | PUBLISHED |
| Assigner | Unknown |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-11-29 12:15:00 UTC |
| Updated | 2024-01-31 17:15:00 UTC |
| Description | Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a malicious file. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products. |
Risk And Classification
EPSS: 0.007200000 probability, percentile 0.724290000 (date 2026-04-01)
CISA KEV: Listed on 2023-11-30; due 2023-12-21; ransomware use Unknown
Problem Types: CWE-190
CISA Known Exploited Vulnerability
| Vendor | |
|---|---|
| Product | Chromium Skia |
| Name | Google Skia Integer Overflow Vulnerability |
| Required Action | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
| Notes | This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://chromereleases.googleblog.com/2023/11/stable-channel-update-for-desktop_28.html ; https://nvd.nist.gov/vuln/detail/CVE-2023-6345 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Operating System | Debian | Debian Linux | 12.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 37 | All | All | All |
| Operating System | Fedoraproject | Fedora | 38 | All | All | All |
| Operating System | Fedoraproject | Fedora | 39 | All | All | All |
| Application | Chrome | All | All | All | All | |
| Application | Microsoft | Edge Chromium | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| lists.fedoraproject.org/archives/list/[email protected]/messag... | lists.fedoraproject.org | Mailing List | |
| lists.fedoraproject.org/archives/list/[email protected]/messag... | lists.fedoraproject.org | Mailing List | |
| lists.fedoraproject.org/archives/list/[email protected]/messag... | lists.fedoraproject.org | ||
| www.debian.org/security/2023/dsa-5569 | www.debian.org | Third Party Advisory | |
| chromereleases.googleblog.com/2023/11/stable-channel-update-for-desktop_28.html | chromereleases.googleblog.com | Release Notes | |
| Chromium, Google Chrome, Microsoft Edge: Multiple Vulnerabilities (GLSA 202401-34) — Gentoo security | security.gentoo.org | ||
| crbug.com/1505053 | crbug.com | Permissions Required | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 284777 Fedora Security Update for chromium (FEDORA-2023-4e555aedeb)
- 284792 Fedora Security Update for chromium (FEDORA-2023-ceaa6b19c1)
- 285117 Fedora Security Update for chromium (FEDORA-2023-145f259a77)
- 379077 Google Chrome Prior to 119.0.6045.199 Multiple Vulnerabilities
- 379084 Microsoft Edge Based on Chromium Prior to 119.0.2151.97/Extended stable Version 118.0.2088.122 Multiple Vulnerabilities
- 506215 Alpine Linux Security Update for qt6-qtwebengine
- 510675 Alpine Linux Security Update for qt5-qtwebengine
- 6000365 Debian Security Update for chromium (DSA 5569-1)
- 691364 Free Berkeley Software Distribution (FreeBSD) Security Update for chromium (8cdd38c7-8ebb-11ee-86bb-a8a1599412c6)
- 691366 Free Berkeley Software Distribution (FreeBSD) Security Update for electron25 (302fc846-860f-482e-a8f6-ee9f254dfacf)
- 691367 Free Berkeley Software Distribution (FreeBSD) Security Update for electron26 (7e1a508f-7167-47b0-b9fc-95f541933a86)
- 691406 Free Berkeley Software Distribution (FreeBSD) Security Update for qt6 (a25b323a-bed9-11ee-bdd6-4ccc6adda413)
- 691407 Free Berkeley Software Distribution (FreeBSD) Security Update for qt5 (a11e7dd1-bed4-11ee-bdd6-4ccc6adda413)
- 710849 Gentoo Linux Chromium, Google Chrome, Microsoft Edge Multiple Vulnerabilities (GLSA 202401-34)
- 710863 Gentoo Linux QtWebEngine Multiple Vulnerabilities (GLSA 202402-14)
- 755389 OpenSUSE Security Update for opera (openSUSE-SU-2023:0396-1)
- 755390 OpenSUSE Security Update for opera (openSUSE-SU-2023:0397-1)