Junglewise Threat Intelligence

CVE-2021-30554: Google Chromium WebGL Use-After-Free Vulnerability

CVE-2021-30554 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Google Chrome, Microsoft Edge, Opera Software Opera. Vendors: Google, Microsoft, Opera Software.

Executive brief

A use-after-free vulnerability exists in the WebGL component of Google Chromium. A remote attacker can exploit this flaw via a specially crafted HTML page to cause heap corruption, potentially leading to arbitrary code execution.

Affected products

  • Google Chrome prior to 91.0.4472.114
  • Microsoft Edge
  • Opera Software Opera

Timeline

  • 2021-06-17: patched: Stable channel update for desktop released.
  • 2021-11-03: disclosed: Vulnerability published and added to CISA KEV catalog.
  • 2021-11-03: kev added
  • 2021-11-03: exploited: Reported as exploited in the wild.