HIGH

CVE-2021-30554

Google Chrome 2021-07-02 CVSS v3.1
CVSS
8.8
KEV

Description

Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Summary dbcve.org

Use-after-free vulnerability in Google Chrome's WebGL implementation prior to version 91.0.4472.114 allows remote attackers to corrupt heap memory via a specially crafted HTML page, potentially enabling arbitrary code execution.

Mitigation

Update Google Chrome to version 91.0.4472.114 or later. Organizations should deploy browser updates through their patch management systems and verify completion across managed endpoints.

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

7.37%
Probability of exploitation in next 30 days
94.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE