PT-2021-4528 · Google+3 · Google Chrome+3

Marcin Towalski

·

Published

2021-07-19

·

Updated

2024-06-15

·

CVE-2021-30602

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 92.0.4515.159
Description The issue is related to a use after free in WebRTC, which allowed an attacker who convinced a user to visit a malicious website to potentially exploit heap corruption via a crafted HTML page. This could allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service using a specially crafted HTML page.
Recommendations For Google Chrome versions prior to 92.0.4515.159, update to version 92.0.4515.159 or later to resolve the issue. As a temporary workaround, consider restricting access to WebRTC functionality until a patch is applied. Avoid using crafted HTML pages that could exploit the heap corruption vulnerability.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2598
ALT-PU-2021-2690
ALT-PU-2021-2747
ALT-PU-2021-2987
ALT-PU-2021-3050
ALT-PU-2021-3436
ALT-PU-2021-3603
BDU:2021-05181
CVE-2021-30602
OPENSUSE-SU-2021:1172-1
OPENSUSE-SU-2021:1180-1
OPENSUSE-SU-2021:1221-1
OPENSUSE-SU-2021_1172-1
OPENSUSE-SU-2021_1221-1
OPENSUSE-SU-2022:0110-1
OPENSUSE-SU-2022_0110-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:10977-1
OPENSUSE-SU-2024:12948-1

Affected Products

Alt Linux
Astra Linux
Google Chrome
Suse