CVE-2021-30633
KEVmassUse-After-Free Sandbox Escape in Chromium Indexed DB API
CISA: Google Chromium Indexed DB API Use-After-Free Vulnerability
Google Chromium's Indexed DB API contains a use-after-free (CWE-416) that a remote attacker who has already compromised the browser's renderer process can trigger via a crafted HTML page to escape the Chromium sandbox. Because the bug requires a prior renderer compromise, it is typically used as a second stage in exploit chains rather than as a standalone attack. Successful exploitation allows code to break out of the browser sandbox and run with elevated privileges on the victim's host. Any user of a Chromium-based browser on an unpatched build is affected, including Google Chrome, Microsoft Edge, Opera, and other Chromium derivatives. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating active exploitation, and EPSS assigns a 32.7% probability of exploitation within 30 days (98th percentile).
What to do: Apply vendor updates immediately per CISA's required action: Google Chrome 94.0.4606.81 or later fixes the flaw, and Microsoft Edge, Opera, Brave and other Chromium-based browsers should be updated to builds incorporating the equivalent Chromium patch. Inventory browser versions fleet-wide and verify that no legacy or unmanaged Chromium installs remain, prioritizing hosts whose users browse untrusted web content. Because in-the-wild exploitation is confirmed (CISA KEV, added 2021-11-03) and this bug is typically chained after a renderer compromise, keep all Chromium components fully patched rather than remediating this flaw in isolation.
| Google Chromium Indexed DB API | Chromium builds prior to the fix released in Google Chrome 94.0.4606.81 (September 2021) |
| Google Chrome | Prior to 94.0.4606.81 |
| Microsoft Edge (Chromium-based) | Builds on unfixed Chromium prior to the equivalent vendor patch |
| Opera (Chromium-based) | Builds on unfixed Chromium prior to the equivalent vendor patch |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- Affected
- Google Chromium Indexed DB API
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- googlefedoraproject
- Products
- chrome, fedora
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H