First published: Thu Apr 01 2021(Updated: )
Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit: chrome-cve-admin@google.com nocma WeChat Open Platform Security Teamleogan WeChat Open Platform Security Teamcheneyxu WeChat Open Platform Security Team
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <91.0.4472.77 | 91.0.4472.77 |
Google Chrome (Trace Event) | <91.0.4472.77 | |
Fedora | =33 | |
Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-30535 is classified as a high severity vulnerability due to its potential for remote exploitation.
To fix CVE-2021-30535, update Google Chrome to version 91.0.4472.77 or later.
CVE-2021-30535 can lead to heap corruption, which may allow an attacker to execute arbitrary code.
Yes, CVE-2021-30535 affects versions of Google Chrome prior to 91.0.4472.77.
Yes, Fedora versions 33 and 34 are affected by CVE-2021-30535 and should be updated accordingly.