CRITICAL

CVE-2021-30633

Google Chrome 2021-10-08 CVSS v3.1
CVSS
9.6
KEV

Description

Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

Summary dbcve.org

Use-after-free vulnerability in Google Chrome's Indexed DB API prior to version 93.0.4577.82. An attacker who has already compromised the renderer process can exploit this to potentially escape the sandbox isolation via a crafted HTML page.

Mitigation

Update Google Chrome to version 93.0.4577.82 or later to patch the vulnerability. Organizations should deploy browser updates across all affected endpoints.

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

33.18%
Probability of exploitation in next 30 days
98.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE