CVE-2023-4354 is a high-severity heap buffer overflow vulnerability in Skia, affecting Google Chrome versions prior to 116.0.5845.96, as well as various Debian and Fedora distributions. A remote attacker could exploit this by tricking a user into visiting a crafted HTML page, potentially leading to heap corruption and allowing the attacker to compromise the renderer process. With a CVSS score of 8.8, this vulnerability presents a high risk due to its network-based attack vector and potential for high impact on confidentiality, integrity, and availability. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in CISA's KEV catalog, indicating it is not actively exploited in the wild. Community discussion and media coverage are also minimal, suggesting low public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 116.0.5845.96, < 116.0.5845.96CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 116.0.5845.96CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.