CVE detail
CVE-2023-6345
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
Google warns of in-the-wild exploitation of CVE-2023-7024, a new Chrome vulnerability, the eighth documented this year.
newswww.securityweek.comDec 21, 2023, 9:50 AM- Google addressed a new actively exploited Chrome zero-daySecurity Affairs
Google has released emergency updates to address a new actively exploited zero-day vulnerability in the Chrome browser. Google has released emergency updates to address a new zero-day vulnerability, tracked as CVE-2023-7024, in its web browser Chrome. The flaw has been addressed with the release of version 120.0.6099.129 for Mac,Linux and 120.0.6099.129/130 for Windows which will […]
newssecurityaffairs.comDec 20, 2023, 11:52 PM - Chrome 120 Patches 10 VulnerabilitiesSecurityWeek
Chrome 120 was released in the stable channel with patches for 10 vulnerabilities, including five externally reported flaws.
newswww.securityweek.comDec 6, 2023, 2:28 PM - 4th December – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 4th December, please download our Threat_Intelligence Bulletin. TOP ATTACKS AND BREACHES Check Point Research provides highlights about Cyber Av3ngers group activity, which has taken responsibility on defacing workstations at Pennsylvania’s Aliquippa municipal water authority. Following the attack, CISA has published an advisory about this […]
vendorresearch.checkpoint.comDec 4, 2023, 9:38 AM - Week in review: PoC for Splunk Enterprise RCE flaw released, scope of Okta breach widensHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Vulnerability disclosure: Legal risks and ethical considerations for researchers In this Help Net Security interview, Eddie Zhang, Principal Consultant at Project Black, explores the complex and often controversial world of vulnerability disclosure in cybersecurity. How passkeys are reshaping user security and convenience In this Help Net Security interview, Anna Pobletts, Head of Passwordless at 1Password, talks about passkey adoption and … More →
newswww.helpnetsecurity.comDec 3, 2023, 9:00 AM - CISA adds ownCloud and Google Chrome bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs
US CISA added ownCloud and Google Chrome vulnerabilities to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added ownCloud and Google Chrome vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The two issues are: CVE-2023-6345 – The CVE-2023-5217 is a high-severity integer overflow in Skia. Skia is an open-source 2D graphics library that provides […]
newssecurityaffairs.comDec 1, 2023, 11:04 AM - Update now! Chrome fixes actively exploited zero-day vulnerabilityMalwarebytes Labs
Google’s released an update to Chrome which includes seven security fixes. Make sure you’re using the latest version!
newswww.malwarebytes.comNov 29, 2023, 11:00 PM - Google addressed the sixth Chrome Zero-Day vulnerability in 2023Security Affairs
Google released security updates to address a new actively exploited zero-day vulnerability, tracked as CVE-2023-6345, in the Chrome browser. Google on Wednesday released security updates to address a new actively exploited zero-day, tracked as CVE-2023-6345, in the Chrome browser. The CVE-2023-5217 is a high-severity integer overflow in Skia. Skia is an open-source 2D graphics library […]
newssecurityaffairs.comNov 29, 2023, 7:04 PM - Google Patches Seventh Chrome Zero-Day of 2023SecurityWeek
The latest Chrome security update addresses the seventh exploited zero-day vulnerability documented in the browser in 2023.
newswww.securityweek.comNov 29, 2023, 12:18 PM - Google fixes Chrome zero day exploited in the wild (CVE-2023-6345)Help Net Security
Google has released an urgent security update to fix a number of vulnerabilities in Chrome browser, including a zero-day vulnerability (CVE-2023-6345) that is being actively exploited in the wild. About CVE-2023-6345 CVE-2023-6345, reported by Benoît Sevens and Clément Lecigne of Google’s Threat Analysis Group, is due to an integer overflow in Skia – an open source 2D graphics library commonly used as a graphics engine for Google Chrome, ChromeOS, Android, Flutter, and others. The company … More →
newswww.helpnetsecurity.comNov 29, 2023, 11:40 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-5849CVSS 8.8 · High
Integer overflow in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security sever…
- CVE-2023-2136CVSS 9.6 · Critical
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a…
- CVE-2021-21223CVSS 9.6 · Critical
Integer overflow in Mojo in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a cr…
- CVE-2020-15986CVSS 6.5 · Medium
Integer overflow in media in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-15975CVSS 8.8 · High
Integer overflow in SwiftShader in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-15974CVSS 8.8 · High
Integer overflow in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to bypass site isolation via a crafted HTML page.