Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Xu Lin

#40702of 53,625
6.5Total CVSS
Vulnerabilities · 1
PT-2021-3559
6.5
2021-02-26
Google · Google Chrome · CVE-2021-21181
**Name of the Vulnerable Software and Affected Versions** Google Chrome versions prior to 89.0.4389.72 **Description** The issue is related to side-channel information leakage in the autofill component of Google Chrome, which can be exploited by a remote attacker using a crafted HTML page to obtain potentially sensitive information from process memory. This is due to a use-after-free vulnerability in the autofill component. **Recommendations** For versions prior to 89.0.4389.72, update to version 89.0.4389.72 or later to resolve the issue. As a temporary workaround, consider disabling the autofill feature until a patch is available. Restrict access to sensitive information when using Google Chrome until the update is applied.