Update Your Chrome Browser to Patch Yet Another 0-Day Exploited in-the
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-30551 | V8 Type Confusion Zero-Day in Google Chrome (CVE-2021-30551), Exploited in the Wild CVE-2021-30551 is a type confusion flaw (CWE-843) in the V8 JavaScript engine used by Google Chrome and Chromium, which can lead to heap corruption. An attacker triggers it by persuading a user to open a specially crafted HTML page — the browser bug requires user interaction but no privileges or authentication. Successful exploitation could allow a remote attacker to execute code or otherwise corrupt the browser process, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). Anyone running Google Chrome prior to 91.0.4472.101, including Chromium-based packages such as Fedora's chromium, is affected. The flaw was exploited as a zero-day before the fix was released, with Google attributing recent Chrome zero-day attacks including this issue to campaigns against Armenian targets linked to a commercial spyware vendor, and it is listed in CISA's Known Exploited Vulnerabilities catalog. Do: Update Google Chrome to 91.0.4472.101 or later (via chrome://settings/help) and update Fedora's chromium package to the patched build, then verify the version in chrome://version. Fedora/Chromium administrators should apply vendor updates per CISA KEV guidance. Until patched, treat web browsing as a risk vector and avoid opening untrusted links, since exploitation requires loading a crafted web page. | 8.8 | 65% | KEV PoC |
| masshundreds of millions to billions of Chrome/Chromium installs worldwide (Chrome is the world's dominant browser) | |
| CVE-2021-30554 | Use-After-Free in Google Chrome WebGL Exploited in the Wild (CVE-2021-30554) CVE-2021-30554 is a use-after-free vulnerability (CWE-416) in the WebGL component of Google Chrome and the Chromium engine. A remote attacker triggers it by persuading a user to open a crafted HTML page that runs malicious WebGL content, requiring no privileges beyond user interaction. Successful exploitation causes heap corruption, which can potentially enable arbitrary code execution, with the high confidentiality, integrity, and availability impact reflected in its 8.8 CVSS score. Every Chrome/Chromium build prior to 91.0.4472.114 is affected, including Fedora's Chromium package built from that code. The flaw was actively exploited as a zero-day before the fix, is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03, required action: apply vendor updates), and EPSS assigns a 7.4% probability of exploitation within 30 days (94th percentile). Do: Upgrade Google Chrome to 91.0.4472.114 or later (verify the running version via chrome://settings/help) and apply the corresponding Fedora Chromium update, since the upstream fix landed in Chromium 91.0.4472.114 and is carried in all subsequent releases. Other Chromium-based browsers inherit the fix through their own vendors' updates, so patch those as soon as they ship it. This CVE is in CISA's KEV catalog with active exploitation, so prioritize patching, especially for users who browse untrusted web content, rather than waiting for a routine patch cycle. | 8.8 | 7% | KEV |
| mass≈3 billion Chrome/Chromium installations (Chrome holds roughly 65% of desktop browser share) |
Full article284 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJun 18, 2021
Google has rolled out yet another update to Chrome browser for Windows, Mac, and Linux to fix four security vulnerabilities, including one zero-day flaw that's being exploited in the wild.
Tracked as CVE-2021-30554, the high severity flaw concerns a use after free vulnerability in WebGL (aka Web Graphics Library), a JavaScript API for rendering interactive 2D and 3D graphics within the browser.
Successful exploitation of the flaw could mean corruption of valid data, leading to a crash, and even execution of unauthorized code or commands.
The issue was reported to Google anonymously on June 15, Chrome technical program manager Srinivas Sista noted, adding the company is "aware that an exploit for CVE-2021-30554 exists in the wild."
While it's usually the norm to limit details of the vulnerability until a majority of users are updated with the fix, the development comes less than 10 days after Google addressed another zero-day vulnerability exploited in active attacks (CVE-2021-30551).
CVE-2021-30554 is also the eighth zero-day flaw patched by Google since the start of the year.
"I'm happy we are getting better at detecting these exploits and the great partnerships we have to get the vulnerabilities patched, but I remain concerned about how many are being discovered on an ongoing basis and the role of commercial providers," tweeted Shane Huntley, Director of Google's Threat Analysis Group, on June 8.
Chrome users are recommended to update to the latest version (91.0.4472.114) by heading to Settings > Help > 'About Google Chrome' to mitigate the risk associated with the flaw.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/06/update-your-chrome-browser-to-patch-yet.html