Junglewise Threat Intelligence

CVE-2021-30633: Google Chromium Indexed DB API Use-After-Free Vulnerability

CVE-2021-30633 · Severity: critical · CVSS 9.6 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Edge, Opera Software Opera, Google Chrome. Vendors: Google, Microsoft, Opera Software.

Executive brief

A use-after-free vulnerability exists in the Indexed DB API of Google Chromium. A remote attacker who has already compromised the renderer process can exploit this flaw via a crafted HTML page to perform a sandbox escape.

Affected products

  • Google Chrome prior to 93.0.4577.82
  • Microsoft Edge
  • Opera Software Opera

Timeline

  • 2021-09-13: patched: Chrome version 93.0.4577.82 released to address the vulnerability.
  • 2021-11-03: disclosed: Vulnerability published and added to CISA KEV catalog.
  • 2021-11-03: kev added
  • 2021-11-03: exploited: Reported as exploited in the wild.