PT-2021-3533 · Google+3 · Google Chrome+3

Published

2021-06-01

·

Updated

2026-03-18

·

CVE-2021-30554

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 91.0.4472.114
Description The issue is related to a use-after-free vulnerability in the WebGL component of Google Chrome, which can be exploited by a remote attacker using a specially crafted HTML page, potentially leading to heap corruption. This vulnerability has been exploited in real-world attacks.
Recommendations For Google Chrome versions prior to 91.0.4472.114, update to version 91.0.4472.114 or later to resolve the issue. As a temporary workaround, consider restricting access to WebGL functionality until the update is applied.

Exploit

Fix

RCE

DoS

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2063
ALT-PU-2021-2068
ALT-PU-2021-2097
ALT-PU-2021-2118
ALT-PU-2021-2141
BDU:2021-03576
BDU:2021-03583
CVE-2021-30554
OPENSUSE-SU-2021:0898-1
OPENSUSE-SU-2021:0938-1
OPENSUSE-SU-2021:0948-1
OPENSUSE-SU-2021:0949-1
OPENSUSE-SU-2021_0898-1
OPENSUSE-SU-2021_0948-1
OPENSUSE-SU-2021_0949-1
OPENSUSE-SU-2022:0110-1
OPENSUSE-SU-2022_0110-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:10977-1
OPENSUSE-SU-2024:12948-1

Affected Products

Alt Linux
Astra Linux
Google Chrome
Suse