Google Chrome 91.0.4472.164 fixes a new zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-21148 | Heap Buffer Overflow in Google Chrome/Chromium V8 (CVE-2021-21148) CVE-2021-21148 is a heap buffer overflow (out-of-bounds write, CWE-787) in the V8 JavaScript engine used by Google Chrome and Chromium. A remote attacker triggers it by getting a user to open a crafted HTML page, so user interaction is required, but no privileges or special access are needed. Successful exploitation corrupts the heap and can allow the attacker to run code within the browser, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). All Chrome/Chromium builds prior to 88.0.4324.150 are affected, including the chromium packages shipped in Fedora and Debian. Google patched the flaw in an emergency update for what headlines described as a Chrome zero-day, and its inclusion in the CISA Known Exploited Vulnerabilities catalog (added 2021-11-03) confirms exploitation in the wild, despite no public PoC; EPSS estimates a 20% probability of exploitation over the next 30 days (97th percentile). Do: Upgrade Google Chrome/Chromium to 88.0.4324.150 or later on all endpoints, and install the updated chromium packages from Fedora and Debian. Verify fleet-wide browser versions, since a single user opening a malicious page is enough for compromise, and confirm auto-update is enabled on managed browsers. | 8.8 | 20% | KEV |
| mass≈3 billion+ users (Chrome's global install base; essentially every Chrome/Chromium build before 88.0.4324.150 was vulnerable) | |
| CVE-2021-21166 | Race Condition Heap Corruption in Google Chromium (Chrome, Edge, Opera) Google Chromium contains a race condition (CWE-362) that can lead to heap corruption (CWE-122) when the browser processes a crafted HTML page, meaning an attacker can trigger the flaw simply by getting a user to visit an attacker-controlled or malicious webpage. Successful exploitation of the heap corruption could crash the browser and potentially allow the attacker to execute code within the affected browser process. Because the vulnerable code is in the Chromium engine itself, all Chromium-based browsers are potentially affected, including Google Chrome, Microsoft Edge, Opera, and other derived browsers, across desktop and mobile fleets. CISA added CVE-2021-21166 to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming the flaw is being exploited in the wild, though ransomware use is unknown and no public proof-of-concept is available. EPSS currently assigns a 26.7% probability of exploitation within 30 days (98th percentile), and CVSS scoring has not yet been published. Do: Apply the latest patched releases of all Chromium-based browsers in use (Chrome, Edge, Opera, and any derived browsers) per vendor instructions, as required by CISA's KEV listing. Prioritize managed endpoints and any systems where users browse untrusted or internet-facing websites, verify fleet-wide browser versions after updating, and monitor CISA/vendor advisories for ransomware-associated activity since that linkage is currently unknown. | 8.8 | 27% | KEV |
| massbillions of users and installations (Chromium powers Chrome, Edge, Opera and many other browsers) | |
| CVE-2021-21193 | Use-After-Free in Google Chromium Blink Engine Actively Exploited CVE-2021-21193 is a use-after-free (CWE-416) in the Blink rendering engine of Google Chrome, with a CVSS 3.1 score of 8.8 (high). It is triggered when a user loads a crafted HTML page in an affected browser, allowing a remote attacker to corrupt heap memory and potentially execute code in the browser renderer process; the attack requires user interaction but no privileges. Anyone running Google Chrome prior to 89.0.4389.90 is affected, as are users of Fedora and Debian systems running Chromium-based browser packages built from the vulnerable code, per the CISA-supplied vendor and product list. Exploitation is confirmed in the wild: the CVE was added to the CISA KEV on 2021-11-03 with a required action of applying vendor updates, and multiple headlines report zero-day attacks against Chrome that were patched by Google. EPSS estimates a 9.9% probability of exploitation in the next 30 days (95th percentile), and no public proof-of-concept is known. Do: Upgrade Google Chrome to 89.0.4389.90 or later immediately; Fedora and Debian users should apply the updated Chromium packages through their distro security repositories, checking their package manager for the patched version. Because the flaw is being exploited in the wild and requires only that a user open a crafted HTML page, prioritize this patch across all endpoints and treat untrusted web links with caution until browsers are updated; CISA KEV requires remediation per vendor instructions by the designated due date. | 8.8 | 10% | KEV |
| masson the order of 1–3 billion users (Chrome's global install base, plus Chromium-based builds on Fedora and Debian) | |
| CVE-2021-21224 +1 in the same advisory: …21220 | Type Confusion RCE in Google Chrome/Chromium V8 JavaScript Engine CVE-2021-21224 is a type confusion vulnerability (CWE-843) in V8, the JavaScript engine used by Google Chrome and Chromium. An attacker triggers it by luring a user to open a crafted HTML page, causing V8 to mishandle object types during execution. Successful exploitation yields arbitrary code execution inside the Chrome renderer's sandbox, typically chained with a separate sandbox escape for full host compromise. Anyone running Google Chrome prior to 90.0.4430.85, or Chromium as packaged by Debian and Fedora, is affected. Exploitation is confirmed in the wild: Google shipped the fix in April 2021 after active attacks, a public PoC exists (crbug.com/1195777), the bug was observed in exploit-kit attack chains, EPSS assigns an 84% probability of near-term exploitation, and CISA added it to the KEV catalog on 2021-11-03. Do: Update Google Chrome to 90.0.4430.85 or later immediately; Debian and Fedora users should apply the chromium package updates issued by their vendors, per CISA KEV required actions. There is no strong workaround short of disabling JavaScript or restricting browsing to trusted sites. Treat this as urgent, since the flaw was already used in real attacks and exploit-kit chains, where it was typically paired with a sandbox escape for full system compromise. | 8.8 | 84% | KEV PoC |
| masson the order of billions of users (Chrome's global install base exceeds 1 billion desktops; Chromium additionally ships in Debian and Fedora) | |
| CVE-2021-30560 | Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. NVD description · AI analysis pending | 8.8 | 21% |
| — | ||
| CVE-2021-30551 | V8 Type Confusion Zero-Day in Google Chrome (CVE-2021-30551), Exploited in the Wild CVE-2021-30551 is a type confusion flaw (CWE-843) in the V8 JavaScript engine used by Google Chrome and Chromium, which can lead to heap corruption. An attacker triggers it by persuading a user to open a specially crafted HTML page — the browser bug requires user interaction but no privileges or authentication. Successful exploitation could allow a remote attacker to execute code or otherwise corrupt the browser process, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). Anyone running Google Chrome prior to 91.0.4472.101, including Chromium-based packages such as Fedora's chromium, is affected. The flaw was exploited as a zero-day before the fix was released, with Google attributing recent Chrome zero-day attacks including this issue to campaigns against Armenian targets linked to a commercial spyware vendor, and it is listed in CISA's Known Exploited Vulnerabilities catalog. Do: Update Google Chrome to 91.0.4472.101 or later (via chrome://settings/help) and update Fedora's chromium package to the patched build, then verify the version in chrome://version. Fedora/Chromium administrators should apply vendor updates per CISA KEV guidance. Until patched, treat web browsing as a risk vector and avoid opening untrusted links, since exploitation requires loading a crafted web page. | 8.8 | 65% | KEV PoC |
| masshundreds of millions to billions of Chrome/Chromium installs worldwide (Chrome is the world's dominant browser) | |
| CVE-2021-30554 | Use-After-Free in Google Chrome WebGL Exploited in the Wild (CVE-2021-30554) CVE-2021-30554 is a use-after-free vulnerability (CWE-416) in the WebGL component of Google Chrome and the Chromium engine. A remote attacker triggers it by persuading a user to open a crafted HTML page that runs malicious WebGL content, requiring no privileges beyond user interaction. Successful exploitation causes heap corruption, which can potentially enable arbitrary code execution, with the high confidentiality, integrity, and availability impact reflected in its 8.8 CVSS score. Every Chrome/Chromium build prior to 91.0.4472.114 is affected, including Fedora's Chromium package built from that code. The flaw was actively exploited as a zero-day before the fix, is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03, required action: apply vendor updates), and EPSS assigns a 7.4% probability of exploitation within 30 days (94th percentile). Do: Upgrade Google Chrome to 91.0.4472.114 or later (verify the running version via chrome://settings/help) and apply the corresponding Fedora Chromium update, since the upstream fix landed in Chromium 91.0.4472.114 and is carried in all subsequent releases. Other Chromium-based browsers inherit the fix through their own vendors' updates, so patch those as soon as they ship it. This CVE is in CISA's KEV catalog with active exploitation, so prioritize patching, especially for users who browse untrusted web content, rather than waiting for a routine patch cycle. | 8.8 | 7% | KEV |
| mass≈3 billion Chrome/Chromium installations (Chrome holds roughly 65% of desktop browser share) | |
| CVE-2021-30563 | Type Confusion in Google Chrome V8 Engine Exploited in the Wild CVE-2021-30563 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine used by Google Chrome and Chromium. A remote attacker triggers it by luring a user to a crafted HTML page, where mistyped objects in V8 can corrupt the heap. Successful exploitation can lead to heap corruption that the attacker can leverage for code execution within the browser renderer process. Anyone running Google Chrome prior to 91.0.4472.164, or a Chromium-based browser built on the vulnerable V8, is affected. The flaw is confirmed exploited in the wild: it was patched as an actively exploited Chrome zero-day and was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03. Do: Upgrade Google Chrome to 91.0.4472.164 or later immediately (verify the installed version via Help > About Chrome); users of Chromium-based browsers should install their vendor's update containing the patched V8. Because in-the-wild exploitation is confirmed (CISA KEV), treat this as urgent patching and confirm auto-update has actually completed rather than assuming it. | 8.8 | 9% | KEV |
| mass≈3 billion+ Chrome/Chromium installs and users worldwide |
Full article382 words · extracted from securityaffairs.com · click to collapse

Google Chrome 91.0.4472.164 addresses seven security vulnerabilities, including a high severity zero-day flaw exploited in the wild.
Google has released Chrome 91.0.4472.164 for Windows, Mac, and Linux that addresses seven vulnerabilities, including a high severity zero-day vulnerability, tracked as CVE-2021-30563, that has been exploited in the wild.
The CVE-2021-30563 is a “type confusion” issue that affects the V8 JavaScript and WebAssembly engine.
“Google is aware of reports that an exploit for CVE-2021-30563 exists in the wild,” reads Google’s announcement.
Type confusion issues are logical bugs that result from confusion between object types, their exploitation would lead to browser crashes due to buffer overflow, they can also potentially lead to arbitrary code execution. The flaw was discovered by Sergei Glazunov from Google Project Zero.
The IT giant did not share info about the attacks exploiting the flaw either the nature of the threat actors.
None of the issues that were fixed by Google with the new release has been rated as critical, below there is the list of flaws addressed with the release of Google Chrome 91.0.4472.164:
- [$7500][1219082] High CVE-2021-30559: Out of bounds write in ANGLE. Reported by Seong-Hwan Park (SeHwa) of SecunologyLab on 2021-06-11
- [$5000][1214842] High CVE-2021-30541: Use after free in V8. Reported by Richard Wheeldon on 2021-05-31
- [$N/A][1219209] High CVE-2021-30560: Use after free in Blink XSLT. Reported by Nick Wellnhofer on 2021-06-12
- [$TBD][1219630] High CVE-2021-30561: Type Confusion in V8. Reported by Sergei Glazunov of Google Project Zero on 2021-06-14
- [$TBD][1220078] High CVE-2021-30562: Use after free in WebSerial. Reported by Anonymous on 2021-06-15
- [$TBD][1228407] High CVE-2021-30563: Type Confusion in V8. Reported by Anonymous on 2021-07-12
- [$TBD][1221309] Medium CVE-2021-30564: Heap buffer overflow in WebXR. Reported by Ali Merchant, iQ3Connect VR Platform on 2021-06-17
This is the eighth zero-day flaw fixed by Google in the Chrome browser that was exploited by threat actors in the wild this year, the other ones are:
- CVE-2021-21148 – February 4th, 2021
- CVE-2021-21166 – March 2nd, 2021
- CVE-2021-21193 – March 12th, 2021
- CVE-2021-21220 – April 13th, 2021
- CVE-2021-21224 – April 20th, 2021
- CVE-2021-30551 – June 9th, 2021
- CVE-2021-30554 – June 17th, 2021
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Google Chrome)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/120205/security/google-chrome-zero-day-2.html