A second Google Chromium zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-21148 | Heap Buffer Overflow in Google Chrome/Chromium V8 (CVE-2021-21148) CVE-2021-21148 is a heap buffer overflow (out-of-bounds write, CWE-787) in the V8 JavaScript engine used by Google Chrome and Chromium. A remote attacker triggers it by getting a user to open a crafted HTML page, so user interaction is required, but no privileges or special access are needed. Successful exploitation corrupts the heap and can allow the attacker to run code within the browser, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). All Chrome/Chromium builds prior to 88.0.4324.150 are affected, including the chromium packages shipped in Fedora and Debian. Google patched the flaw in an emergency update for what headlines described as a Chrome zero-day, and its inclusion in the CISA Known Exploited Vulnerabilities catalog (added 2021-11-03) confirms exploitation in the wild, despite no public PoC; EPSS estimates a 20% probability of exploitation over the next 30 days (97th percentile). Do: Upgrade Google Chrome/Chromium to 88.0.4324.150 or later on all endpoints, and install the updated chromium packages from Fedora and Debian. Verify fleet-wide browser versions, since a single user opening a malicious page is enough for compromise, and confirm auto-update is enabled on managed browsers. | 8.8 | 20% | KEV |
| mass≈3 billion+ users (Chrome's global install base; essentially every Chrome/Chromium build before 88.0.4324.150 was vulnerable) | |
| CVE-2021-21166 | Race Condition Heap Corruption in Google Chromium (Chrome, Edge, Opera) Google Chromium contains a race condition (CWE-362) that can lead to heap corruption (CWE-122) when the browser processes a crafted HTML page, meaning an attacker can trigger the flaw simply by getting a user to visit an attacker-controlled or malicious webpage. Successful exploitation of the heap corruption could crash the browser and potentially allow the attacker to execute code within the affected browser process. Because the vulnerable code is in the Chromium engine itself, all Chromium-based browsers are potentially affected, including Google Chrome, Microsoft Edge, Opera, and other derived browsers, across desktop and mobile fleets. CISA added CVE-2021-21166 to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming the flaw is being exploited in the wild, though ransomware use is unknown and no public proof-of-concept is available. EPSS currently assigns a 26.7% probability of exploitation within 30 days (98th percentile), and CVSS scoring has not yet been published. Do: Apply the latest patched releases of all Chromium-based browsers in use (Chrome, Edge, Opera, and any derived browsers) per vendor instructions, as required by CISA's KEV listing. Prioritize managed endpoints and any systems where users browse untrusted or internet-facing websites, verify fleet-wide browser versions after updating, and monitor CISA/vendor advisories for ransomware-associated activity since that linkage is currently unknown. | 8.8 | 27% | KEV |
| massbillions of users and installations (Chromium powers Chrome, Edge, Opera and many other browsers) | |
| CVE-2021-21193 | Use-After-Free in Google Chromium Blink Engine Actively Exploited CVE-2021-21193 is a use-after-free (CWE-416) in the Blink rendering engine of Google Chrome, with a CVSS 3.1 score of 8.8 (high). It is triggered when a user loads a crafted HTML page in an affected browser, allowing a remote attacker to corrupt heap memory and potentially execute code in the browser renderer process; the attack requires user interaction but no privileges. Anyone running Google Chrome prior to 89.0.4389.90 is affected, as are users of Fedora and Debian systems running Chromium-based browser packages built from the vulnerable code, per the CISA-supplied vendor and product list. Exploitation is confirmed in the wild: the CVE was added to the CISA KEV on 2021-11-03 with a required action of applying vendor updates, and multiple headlines report zero-day attacks against Chrome that were patched by Google. EPSS estimates a 9.9% probability of exploitation in the next 30 days (95th percentile), and no public proof-of-concept is known. Do: Upgrade Google Chrome to 89.0.4389.90 or later immediately; Fedora and Debian users should apply the updated Chromium packages through their distro security repositories, checking their package manager for the patched version. Because the flaw is being exploited in the wild and requires only that a user open a crafted HTML page, prioritize this patch across all endpoints and treat untrusted web links with caution until browsers are updated; CISA KEV requires remediation per vendor instructions by the designated due date. | 8.8 | 10% | KEV |
| masson the order of 1–3 billion users (Chrome's global install base, plus Chromium-based builds on Fedora and Debian) |
Full article292 words · extracted from securityaffairs.com · click to collapse

For the second time in a week, a Chromium zero-day remote code execution exploit code has been released on Twitter, multiple browsers impacted.
A new Chromium zero-day remote code execution exploit has been released on Twitter this week, like the previous one that affects current versions of Google Chrome, Microsoft Edge, and likely other Chromium-based browsers.
The exploit for the new vulnerability was publicly released by a security researcher that goes online with the handle frust. The exploit demonstrated by the expert triggers the issue to open the Windows Notepad application.
Early this week, the Indian security researcher Rajvardhan Agarwal has publicly released a proof-of-concept exploit code for a recently discovered vulnerability that affects Google Chrome, Microsoft Edge, and other Chromium-based browsers (i.e. Opera, Brave).
The researchers uploaded the PoC code on GitHub and announced its availability via Twitter. According to The Record, the PoC code released by the experts was the same exploited by the security duo composed of Bruno Keith (@bkth_) & Niklas Baumstark (@_niklasb) of Dataflow during the Pwn2Own 2021 hacking contest.
Google addressed this issue with the release of the Chrome 89.0.4389.128 version.
Both remote code execution vulnerabilities disclosed this week could not escape Chromium’s sandbox, which means that attackers have to chain them with a sandbox escape exploit to executing arbitrary code on the underlying system.
Since January, Google has already addressed other zero-day issues in Chrome that have been actively exploited in the wild, including CVE-2021-21148, CVE-2021-21166, and CVE-2021-21193.
If you want to receive the weekly Security Affairs Newsletter for free subscribe here.
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Chromium zero-day)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/116844/hacking/google-chromium-zero.html