PT-2021-5562 · Google+3 · Chrome Os+5
Published
2021-09-02
·
Updated
2024-06-15
·
CVE-2021-30611
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Chromium versions prior to 93.0.4577.63
Google Chrome on Linux, ChromeOS versions prior to 93.0.4577.63
Description
The issue is related to a use after free in WebRTC, which can potentially allow an attacker to exploit heap corruption via a crafted HTML page. This could impact the confidentiality, integrity, and availability of information. An attacker who convinces a user to install a malicious extension may exploit this issue.
Recommendations
For Chromium versions prior to 93.0.4577.63, update to version 93.0.4577.63 or later.
For Google Chrome on Linux, ChromeOS versions prior to 93.0.4577.63, update to version 93.0.4577.63 or later.
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Chrome Os
Chromium
Google Chrome
Suse