HIGH
CVE-2021-30554
CVSS
8.8
KEV
Description
Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Summary dbcve.org
Use-after-free vulnerability in Google Chrome's WebGL implementation prior to version 91.0.4472.114 allows remote attackers to corrupt heap memory via a specially crafted HTML page, potentially enabling arbitrary code execution.
Mitigation
Update Google Chrome to version 91.0.4472.114 or later. Organizations should deploy browser updates through their patch management systems and verify completion across managed endpoints.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
7.37%
Probability of exploitation in next 30 days
94.2th percentile
References
https://chromereleases.googleblog.com/2021/06/stable-channel-update-for-desktop_17.html
Release Notes
https://crbug.com/1219857
Permissions Required
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ETMZL6IHCTCTREEL434BQ4THQ7EOHJ43/
Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PAT6EOXVQFE6JFMFQF4IKAOUQSHMHL54/
Release Notes
https://security.gentoo.org/glsa/202107-06
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30554
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.