CVE-2023-6345: Integer overflow in Skia
Chromium: CVE-2023-6345 Integer overflow in Skia
Other sources
Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a malicious file. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.
— CISA
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2023-6345 exists in the wild.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.129-1~deb11u1Fixed in 119.0.6045.199-1~deb12u1Fixed in 120.0.6099.129-1~deb12u1Fixed in 120.0.6099.129-1 - Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 119.0.6045.199 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.129-1~deb11u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 119.0.6045.199-1~deb12u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.129-1~deb12u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.129-1 - Compensating control
Discontinue use of the product if mitigations are unavailable.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-6345?
CVE-2023-6345 is an integer overflow vulnerability in Skia in Google Chrome prior to version 119.0.6045.199.
How severe is CVE-2023-6345?
CVE-2023-6345 has a high severity rating according to Chromium.
Which software is affected by CVE-2023-6345?
Microsoft Edge (Chromium-based) versions up to 119.0.2151.97 are affected by CVE-2023-6345.
Can a remote attacker exploit CVE-2023-6345?
Yes, a remote attacker who has compromised the renderer process can potentially perform a sandbox escape using a malicious file.
How can I fix CVE-2023-6345 in Microsoft Edge (Chromium-based)?
To fix CVE-2023-6345 in Microsoft Edge (Chromium-based), update to version 119.0.2151.97 or later.