CVE-2021-30554
KEVmassUse-After-Free in Google Chrome WebGL Exploited in the Wild (CVE-2021-30554)
CISA: Google Chromium WebGL Use-After-Free Vulnerability
CVE-2021-30554 is a use-after-free vulnerability (CWE-416) in the WebGL component of Google Chrome and the Chromium engine. A remote attacker triggers it by persuading a user to open a crafted HTML page that runs malicious WebGL content, requiring no privileges beyond user interaction. Successful exploitation causes heap corruption, which can potentially enable arbitrary code execution, with the high confidentiality, integrity, and availability impact reflected in its 8.8 CVSS score. Every Chrome/Chromium build prior to 91.0.4472.114 is affected, including Fedora's Chromium package built from that code. The flaw was actively exploited as a zero-day before the fix, is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03, required action: apply vendor updates), and EPSS assigns a 7.4% probability of exploitation within 30 days (94th percentile).
What to do: Upgrade Google Chrome to 91.0.4472.114 or later (verify the running version via chrome://settings/help) and apply the corresponding Fedora Chromium update, since the upstream fix landed in Chromium 91.0.4472.114 and is carried in all subsequent releases. Other Chromium-based browsers inherit the fix through their own vendors' updates, so patch those as soon as they ship it. This CVE is in CISA's KEV catalog with active exploitation, so prioritize patching, especially for users who browse untrusted web content, rather than waiting for a routine patch cycle.
| Google Chrome | all versions prior to 91.0.4472.114 |
| Google Chromium | all versions prior to 91.0.4472.114 |
| Fedora Project Fedora (Chromium package) | Chromium builds prior to 91.0.4472.114 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- Affected
- Google Chromium WebGL
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- googlefedoraproject
- Products
- chrome, fedora
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H