Critical severity9.6NVD Advisory· Published Jul 16, 2024· Updated Jun 17, 2026
CVE-2023-4860
CVE-2023-4860
Description
Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Affected products
4Patches
Vulnerability mechanics
References
2- chromereleases.googleblog.com/2023/07/stable-channel-update-for-desktop.htmlnvdRelease Notes
- issues.chromium.org/issues/40064341nvdPermissions Required
News mentions
0No linked articles in our index yet.