ZeroHour

CVE-2021-30554

KEVmass

Use-After-Free in Google Chrome WebGL Exploited in the Wild (CVE-2021-30554)

CISA: Google Chromium WebGL Use-After-Free Vulnerability

CVSS 3.1
8.8 high
EPSS
7%p94
Published
()
KEV added
AI analysis

CVE-2021-30554 is a use-after-free vulnerability (CWE-416) in the WebGL component of Google Chrome and the Chromium engine. A remote attacker triggers it by persuading a user to open a crafted HTML page that runs malicious WebGL content, requiring no privileges beyond user interaction. Successful exploitation causes heap corruption, which can potentially enable arbitrary code execution, with the high confidentiality, integrity, and availability impact reflected in its 8.8 CVSS score. Every Chrome/Chromium build prior to 91.0.4472.114 is affected, including Fedora's Chromium package built from that code. The flaw was actively exploited as a zero-day before the fix, is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03, required action: apply vendor updates), and EPSS assigns a 7.4% probability of exploitation within 30 days (94th percentile).

What to do: Upgrade Google Chrome to 91.0.4472.114 or later (verify the running version via chrome://settings/help) and apply the corresponding Fedora Chromium update, since the upstream fix landed in Chromium 91.0.4472.114 and is carried in all subsequent releases. Other Chromium-based browsers inherit the fix through their own vendors' updates, so patch those as soon as they ship it. This CVE is in CISA's KEV catalog with active exploitation, so prioritize patching, especially for users who browse untrusted web content, rather than waiting for a routine patch cycle.

Affected
Google Chromeall versions prior to 91.0.4472.114
Google Chromiumall versions prior to 91.0.4472.114
Fedora Project Fedora (Chromium package)Chromium builds prior to 91.0.4472.114
Estimated exposure
mass≈3 billion Chrome/Chromium installations (Chrome holds roughly 65% of desktop browser share) — Estimated from Chrome's dominant desktop-browser market share (~65%) and reported user base on the order of three billion, since every build before 91.0.4472.114 was vulnerable at disclosure; Fedora's Chromium rebuild adds a smaller but…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium WebGL
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlefedoraproject
Products
chrome, fedora
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news