PT-2021-2015 · Google+2 · Google Chrome+2

Khalil

·

Published

2021-02-16

·

Updated

2024-06-15

·

CVE-2021-21155

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 88.0.4324.182
Description The issue is a heap buffer overflow in the Tab Strip element of Google Chrome on Windows, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This could enable the attacker to execute arbitrary code.
Recommendations For versions prior to 88.0.4324.182, update to version 88.0.4324.182 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable HTML pages until the update is applied.

Exploit

Fix

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00851
CVE-2021-21155
DSA-4858-1
OPENSUSE-SU-2021:0392-1
OPENSUSE-SU-2021:0401-1
OPENSUSE-SU-2021:0413-1
OPENSUSE-SU-2021_0392-1
OPENSUSE-SU-2021_0413-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1

Affected Products

Astra Linux
Google Chrome
Suse