Skip to content
COOEY

FAIL › dossier

Chromium Skia

PRODUCT

· dossier confidence 20%

Chromium Skia is a graphics library with a regular patch cycle but a concerning track record of high-severity RCE vulnerabilities in the Skia component that have been actively exploited in the wild, requiring vigilant monitoring and rapid patching.

PROFILE
CategorysoftwareWhat they doChromium Skia is a 2D graphics library used by Google Chrome and other Chromium-based browsers for rendering graphics and images. Websitehttps://skia.org ↗
SECURITY POSTURE

Maintains a regular patch cycle with frequent security updates, but has a history of high-severity RCE vulnerabilities in the Skia component that were actively exploited in the wild.

Notable failures
  • CVE-2023-6345: Skia integer overflow allowing sandbox escape via malicious file, actively exploited in the wild
  • CVE-2023-2136: Chrome Skia integer overflow vulnerability
Patterns: repeated unpatched integer overflow RCEs in Skia; active exploitation of Skia vulnerabilities in the wild
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2023-11-30 CVE-2023-6345 high A Google Skia integer overflow vulnerability allowed sandbox escape via a malicious file, actively exploited in the wild and impacting Chrome, ChromeOS, Android, and Flutter products.
2023-04-21 CVE-2023-2136 high Google Chrome Skia Integer Overflow Vulnerability
DOSSIER SOURCES
Open questions: Skia's current patching SLA · Skia's current sandboxing architecture
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-15 04:00:48.200734+00:00