Google · Skia · CVE-2021-21147
Name of the Vulnerable Software and Affected Versions:
Google Chrome versions prior to 88.0.4324.146
Description:
The issue is related to an inappropriate implementation in Skia, a graphic library used by Google Chrome, which allowed a local attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. This could be exploited by a remote attacker using a specially crafted HTML page, potentially leading to spoofing attacks.
Recommendations:
For Google Chrome versions prior to 88.0.4324.146, update to version 88.0.4324.146 or later to resolve the issue. As a temporary workaround, consider restricting the use of crafted HTML pages to minimize the risk of exploitation.