FAIL › dossier
Chromium Skia
PRODUCT· dossier confidence 20%
Chromium Skia is a graphics library with a regular patch cycle but a concerning track record of high-severity RCE vulnerabilities in the Skia component that have been actively exploited in the wild, requiring vigilant monitoring and rapid patching.
PROFILE
CategorysoftwareWhat they doChromium Skia is a 2D graphics library used by Google Chrome and other Chromium-based browsers for rendering graphics and images.
Websitehttps://skia.org ↗
SECURITY POSTURE
Maintains a regular patch cycle with frequent security updates, but has a history of high-severity RCE vulnerabilities in the Skia component that were actively exploited in the wild.
Notable failures
- CVE-2023-6345: Skia integer overflow allowing sandbox escape via malicious file, actively exploited in the wild
- CVE-2023-2136: Chrome Skia integer overflow vulnerability
Patterns: repeated unpatched integer overflow RCEs in Skia; active exploitation of Skia vulnerabilities in the wild
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2023-11-30 | CVE-2023-6345 | high | A Google Skia integer overflow vulnerability allowed sandbox escape via a malicious file, actively exploited in the wild and impacting Chrome, ChromeOS, Android, and Flutter products. |
| 2023-04-21 | CVE-2023-2136 | high | Google Chrome Skia Integer Overflow Vulnerability |
DOSSIER SOURCES
- Chrome 151 Security Update Fixes 41 Browser Flaws · aboutinfosec.com
- Chrome Releases: 2026 · chromereleases.googleblog.com
- Chrome Releases · chromereleases.googleblog.com
Open questions: Skia's current patching SLA · Skia's current sandboxing architecture
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-15 04:00:48.200734+00:00