CVE-2021-30554: Google Chromium WebGL Use-After-Free Vulnerability
Google Chromium WebGL contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Other sources
Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 91.0.4472.114
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2021-30554?
CVE-2021-30554 is a use-after-free vulnerability in Google Chromium WebGL that can be exploited via a crafted HTML page.
Which web browsers are affected by CVE-2021-30554?
Web browsers that utilize Chromium, including Google Chrome and Microsoft Edge, are affected by CVE-2021-30554.
What is the severity of CVE-2021-30554?
CVE-2021-30554 has a severity score of 8.8, which is considered high.
How can CVE-2021-30554 be exploited?
CVE-2021-30554 can be exploited by a remote attacker through heap corruption via a crafted HTML page.
How can I fix CVE-2021-30554?
To fix CVE-2021-30554, users should update their web browsers to the latest version provided by the respective vendors.