Executive brief
A use-after-free vulnerability exists in the WebGL component of Google Chromium. A remote attacker can exploit this flaw via a specially crafted HTML page to cause heap corruption, potentially leading to arbitrary code execution.
Affected products
- Google Chrome prior to 91.0.4472.114
- Microsoft Edge
- Opera Software Opera
Timeline
- 2021-06-17: patched: Stable channel update for desktop released.
- 2021-11-03: disclosed: Vulnerability published and added to CISA KEV catalog.
- 2021-11-03: kev added
- 2021-11-03: exploited: Reported as exploited in the wild.