Vulnerability record · CVE-2023-6345 · published 29 November 2023
CVE-2023-6345: Chrome Skia integer overflow enables sandbox escape
Google · Chrome
An integer overflow in Skia in Google Chrome before 119.0.6045.199 lets a remote attacker who already controls the renderer process escape the browser sandbox using a malicious file. Because it defeats the sandbox, a renderer compromise can escalate to full host impact, which is why it was added to CISA KEV.
Description
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.6, active inclusion in CISA KEV and a sandbox escape that turns renderer compromise into host compromise justify critical priority.
What it is
An integer overflow in Skia in Google Chrome before 119.0.6045.199 lets a remote attacker who already controls the renderer process escape the browser sandbox using a malicious file. Because it defeats the sandbox, a renderer compromise can escalate to full host impact, which is why it was added to CISA KEV.
Impact
An attacker with renderer code execution gains the ability to break out of the Chrome sandbox and run code at the browser's privilege level on the underlying operating system.
Attack surface
Reached remotely over the network via a crafted file processed by Skia; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N), but the description states the attacker must first have compromised the renderer process.
Exploitation
Listed in CISA KEV with a 2023-12-21 remediation due date, indicating known exploitation; EPSS 30-day probability is 0.16468 (96.8th percentile). No ransomware campaign use is documented.
What to do
- Update Chrome to 119.0.6045.199 or later, and apply matching Edge Chromium, Debian and Fedora updates.
- Follow CISA KEV required action: apply vendor mitigations or discontinue use of the product if none are available.
- Keep the browser sandbox enabled and avoid disabling it for compatibility.
- Restrict untrusted file downloads and rendering paths where feasible.
- Track vendor advisories for Chromium-based browsers and patch on the same cadence.
Detection
- Monitor for Chrome renderer crashes or sandbox-escape alerts in endpoint telemetry.
- Hunt for unexpected child processes or code execution originating from browser renderer processes.
- Review proxy and download logs for malicious files delivered to Chrome users.
- Correlate endpoint detections with known exploitation activity around the KEV due date.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-6345 to the Known Exploited Vulnerabilities catalog on 30 November 2023 as "Google Skia Integer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 21 December 2023.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-6345 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-6345), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.