CVE-2021-4098: Insufficient data validation in Mojo
Insufficient data validation in Mojo in Google Chrome prior to 96.0.4664.110 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2021-4098?
CVE-2021-4098 is a vulnerability in Mojo in Google Chrome prior to 96.0.4664.110 that allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
How severe is CVE-2021-4098?
CVE-2021-4098 has a severity score of 7.4 (high).
Which software versions are affected by CVE-2021-4098?
Google Chrome versions prior to 96.0.4664.110 and certain versions of chromium package in Debian, including 90.0.4430.212-1~deb10u1.
How can I fix CVE-2021-4098?
To fix CVE-2021-4098, update Google Chrome to version 96.0.4664.110 or later, or update the chromium package in Debian to the patched versions mentioned in the Debian security tracker.
Where can I find more information about CVE-2021-4098?
You can find more information about CVE-2021-4098 in the references provided: [Chrome Releases Blog](https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop_13.html), [Chromium Bug Tracker](https://crbug.com/1263457), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2021-4098).