EXPOSURES › CVE-2023-6345
CVE-2023-6345
HIGH ⌖ ON CISA KEV · EXPLOITEDA Google Skia integer overflow vulnerability allowed sandbox escape via a malicious file, actively exploited in the wild and impacting Chrome, ChromeOS, Android, and Flutter products.
An integer overflow in Google Skia enabled a renderer process compromise to potentially escape the sandbox, impacting numerous Google products and potentially derivatives. DIB organizations using these products or their components must immediately patch to prevent potential data exfiltration or system compromise, impacting NIST 800-171 controls related to data protection and vulnerability management.
Shame score — The vulnerability's active exploitation and broad impact across critical Google products demonstrates a significant failure in secure coding practices and risk management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a malicious file. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |