PT-2021-7877 · Google+1 · Google Chrome+1

Published

2021-07-20

·

Updated

2023-08-12

·

CVE-2021-4320

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 92.0.4515.107
Description The issue is related to a use after free in Blink, allowing a remote attacker who has compromised the renderer process to perform arbitrary read/write via a crafted HTML page. This can potentially bypass existing security restrictions. The estimated number of potentially affected devices worldwide is not specified.
Recommendations For versions prior to 92.0.4515.107, update to version 92.0.4515.107 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable HTML pages until the update is applied.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2023-04403
CVE-2021-4320
DSA-5046-1

Affected Products

Astra Linux
Google Chrome