Executive brief
A use-after-free vulnerability in site isolation in Google Chrome allows a remote attacker who has already compromised the renderer process to perform a sandbox escape. Exploitation is achieved via a specially crafted HTML page and requires user interaction.
Affected products
- Google Chrome < 86.0.4240.198
Timeline
- 2021-01-08: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: advisory: CISA Advisory Publication