CVE-2021-30564: Heap buffer overflow in WebXR
Published Jun 17, 2021
·Updated
Heap buffer overflow in WebXR in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Ali Merchant, iQ3Connect VR Platform
Affected Software
2 affected componentsFixes available
Google Chrome<91.0.4472.164
91.0.4472.164
Google Chrome<91.0.4472.164
Event History
Jun 17, 2021
CVE Published
12:00 AM
Aug 3, 2021
CVE Published
via MITRE·06:25 PM
Data Sourced
via MITRE·06:25 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2021-30564?
CVE-2021-30564 has a high severity rating due to potential remote exploitation and heap corruption risk.
2
How do I fix CVE-2021-30564?
To fix CVE-2021-30564, update Google Chrome to the latest version 91.0.4472.164 or later.
3
What type of vulnerability is CVE-2021-30564?
CVE-2021-30564 is classified as a heap buffer overflow vulnerability in WebXR of Google Chrome.
4
Who is affected by CVE-2021-30564?
Users running Google Chrome versions prior to 91.0.4472.164 are affected by CVE-2021-30564.
5
Can CVE-2021-30564 be exploited remotely?
Yes, CVE-2021-30564 allows remote attackers to exploit the vulnerability via a crafted HTML page.