ZeroHour

CVE-2021-30633

KEVmass

Use-After-Free Sandbox Escape in Chromium Indexed DB API

CISA: Google Chromium Indexed DB API Use-After-Free Vulnerability

CVSS 3.1
9.6 critical
EPSS
33%p98
Published
()
KEV added
AI analysis

Google Chromium's Indexed DB API contains a use-after-free (CWE-416) that a remote attacker who has already compromised the browser's renderer process can trigger via a crafted HTML page to escape the Chromium sandbox. Because the bug requires a prior renderer compromise, it is typically used as a second stage in exploit chains rather than as a standalone attack. Successful exploitation allows code to break out of the browser sandbox and run with elevated privileges on the victim's host. Any user of a Chromium-based browser on an unpatched build is affected, including Google Chrome, Microsoft Edge, Opera, and other Chromium derivatives. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating active exploitation, and EPSS assigns a 32.7% probability of exploitation within 30 days (98th percentile).

What to do: Apply vendor updates immediately per CISA's required action: Google Chrome 94.0.4606.81 or later fixes the flaw, and Microsoft Edge, Opera, Brave and other Chromium-based browsers should be updated to builds incorporating the equivalent Chromium patch. Inventory browser versions fleet-wide and verify that no legacy or unmanaged Chromium installs remain, prioritizing hosts whose users browse untrusted web content. Because in-the-wild exploitation is confirmed (CISA KEV, added 2021-11-03) and this bug is typically chained after a renderer compromise, keep all Chromium components fully patched rather than remediating this flaw in isolation.

Affected
Google Chromium Indexed DB APIChromium builds prior to the fix released in Google Chrome 94.0.4606.81 (September 2021)
Google ChromePrior to 94.0.4606.81
Microsoft Edge (Chromium-based)Builds on unfixed Chromium prior to the equivalent vendor patch
Opera (Chromium-based)Builds on unfixed Chromium prior to the equivalent vendor patch
Estimated exposure
massMulti-billion — billions of browser installs across Chrome, Edge, Opera and other Chromium derivatives, of which unpatched installations at patch time numbered… — Chromium is the engine behind Google Chrome (3+ billion users) plus Microsoft Edge, Opera and other derivatives, so exposure is plausibly in the billions of installs with the vulnerable population shrinking as vendor patches are adopted.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium Indexed DB API
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlefedoraproject
Products
chrome, fedora
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news