Executive brief
A use-after-free vulnerability in the Blink engine of Google Chrome allows a remote attacker to potentially exploit heap corruption via a specially crafted HTML page. This vulnerability has been observed being exploited in the wild.
Affected products
- Google Chrome prior to 89.0.4389.90
- Microsoft Edge
- Opera Software Opera
Timeline
- 2021-03-12: patched: Stable channel update for desktop released.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.