CRITICAL
CVE-2021-30633
CVSS
9.6
KEV
Description
Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Summary dbcve.org
Use-after-free vulnerability in Google Chrome's Indexed DB API prior to version 93.0.4577.82. An attacker who has already compromised the renderer process can exploit this to potentially escape the sandbox isolation via a crafted HTML page.
Mitigation
Update Google Chrome to version 93.0.4577.82 or later to patch the vulnerability. Organizations should deploy browser updates across all affected endpoints.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
33.18%
Probability of exploitation in next 30 days
98.3th percentile
References
https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop.html
Release Notes
https://crbug.com/1247766
Permissions Required
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4DDW7HAHTS3SDVXBQUY4SURELO5D4X7R/
Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PM7MOYYHJSWLIFZ4TPJTD7MSA3HSSLV2/
Release Notes
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30633
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.