SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Google Fixes Chrome’s Sixth Zero-day Vulnerability in 2023

Google Fixes Chrome’s Sixth Zero-day Vulnerability in 2023

In response to ongoing attacks exploiting a security vulnerability, Google released a security patch on 28th November, effectively addressing the sixth zero-day flaw in the Chrome browser this year. The company has officially acknowledged the existence of an exploit for the identified security flaw,...

Nov 28, 2023By Shwetha G2 min read

In response to ongoing attacks exploiting a security vulnerability, Google released a security patch on 28th November, effectively addressing the sixth zero-day flaw in the Chrome browser this year. The company has officially acknowledged the existence of an exploit for the identified security flaw, tracked as CVE-2023-6345, in a recently published security advisory.

The Zero-Day Vulnerability CVE-2023-6345: This newly patched high-severity zero-day vulnerability is rooted in an integer overflow vulnerability within the Skia open-source 2D graphics library. Skia, a graphics engine for products such as ChromeOS, Android, and Flutter, makes this vulnerability particularly impactful. The risks associated with this flaw range from system crashes to the potential execution of arbitrary code.This flaw was discovered by Benoît Sevens and Clément Lecigne, security researchers at Google’s Threat Analysis Group (TAG), the bug was reported on 28th November. Google has taken precautionary measures by restricting access to bug details and links until most users have updated their Chrome browsers. This approach aims to minimize the risk of threat actors exploiting the vulnerability based on the released technical information.Updated Patch Addresses The Below Vulnerabilities Along With CVE-2023-6345CVE-2023-6348: Type Confusion in SpellcheckCVE-2023-6347: Use after free in MojoCVE-2023-6346: Use after free in WebAudioCVE-2023-6350: Out-of-bounds memory access in libavifCVE-2023-6351: Use after free in libavifChrome’s Zero-Day Vulnerabilities Addressed In 2023: With this recent emergency update, Google has now addressed a total of six zero-day vulnerabilities in Chrome since the beginning of the year. The list includes:

  1. CVE-2023-2033 (CVSS score: 8.8) – Type confusion in V8
  2. CVE-2023-2136 (CVSS score: 9.6) – Integer overflow in Skia
  3. CVE-2023-3079 (CVSS score: 8.8) – Type confusion in V8
  4. CVE-2023-4863 (CVSS score: 8.8) – Heap buffer overflow in WebP
  5. CVE-2023-5217 (CVSS score: 8.8) – Heap buffer overflow in vp8 encoding in libvpx

Affected ProductsGoogle Chrome version before 119.0.6045.199.

SolutionGoogle has released Chrome version 119.0.6045.199 for macOS and Linux and 119.0.6045.199/.200 for Windows.

SanerNow detects these vulnerabilities and automatically fixes them through patch management by applying security updates. We strongly recommend applying the security updates as soon as possible.

Featured Posts

Open Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras
Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

CVE Research

Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

A single operator compromised 14,530+ Dahua cameras across Ukraine and Russia in 35 days, chaining credential brute-force, a CVE-2021-33044/33045 authentication bypass, and P2P relay abuse to plant a persistent backdoor and harvest transferable admin access.

Aug 21, 2026

Open Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE Research

Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

Aug 19, 2026

Open No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners
No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

CVE Research

No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

Aug 19, 2026

Open Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies
Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

CVE Research

Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

Aug 19, 2026

Google Fixes Chrome’s Sixth Zero-day Vulnerability in 2023 | SecPod