Use-after-free in Google Chrome - CVE-2021-30604
Published: August 17, 2021 / Updated: August 19, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in ANGLE. A remote attacker can trick the victim to visit a specially crafted web page, trigger a use-after-free error and execute arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Microsoft Edge
Gentoo Linux
Fedora
qt5-qtwebengine
chromium
How to mitigate CVE-2021-30604
Microsoft Edge - update to 92.0.902.78
qt5-qtwebengine - update to 5.15.8-2.fc34
chromium - addressed in versions 93.0.4577.63-1.el8, 93.0.4577.63-1.fc33, 93.0.4577.63-1.fc34, 93.0.4577.63-1.fc35