Executive brief
A use-after-free vulnerability exists in the Indexed DB API of Google Chromium. A remote attacker who has already compromised the renderer process can exploit this flaw via a crafted HTML page to perform a sandbox escape.
Affected products
- Google Chrome prior to 93.0.4577.82
- Microsoft Edge
- Opera Software Opera
Timeline
- 2021-09-13: patched: Chrome version 93.0.4577.82 released to address the vulnerability.
- 2021-11-03: disclosed: Vulnerability published and added to CISA KEV catalog.
- 2021-11-03: kev added
- 2021-11-03: exploited: Reported as exploited in the wild.