Executive brief
A use-after-free vulnerability in the Blink engine of Google Chromium allows remote attackers to execute arbitrary code or cause heap corruption via a specially crafted HTML page. This vulnerability was exploited in the wild prior to being patched.
Affected products
- Google Chrome prior to 89.0.4389.128
- Microsoft Edge
- Opera Opera
Timeline
- 2021-04-13: patched: Chrome stable channel update 89.0.4389.128 released
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed