CVE-2021-4100: Object lifecycle issue in ANGLE
Published Nov 19, 2021
·Updated
Object lifecycle issue in ANGLE in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Aki Helin(Solita)
Affected Software
3 affected componentsFixes available
debian/chromium<=90.0.4430.212-1~deb10u1
116.0.5845.180-1~deb11u1118.0.5993.70-1~deb11u1116.0.5845.180-1~deb12u1118.0.5993.70-1~deb12u1118.0.5993.70-1
Google Chrome<96.0.4664.110
96.0.4664.110
Google Chrome<96.0.4664.110
Event History
Nov 19, 2021
CVE Published
12:00 AM
Feb 11, 2022
CVE Published
via MITRE·10:55 PM
Data Sourced
via MITRE·10:55 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2021-4100?
CVE-2021-4100 is considered a high severity vulnerability due to its potential for remote code execution through heap corruption.
2
How do I fix CVE-2021-4100?
To fix CVE-2021-4100, users should update Google Chrome to version 96.0.4664.110 or later.
3
Which versions are affected by CVE-2021-4100?
CVE-2021-4100 affects versions of Google Chrome before 96.0.4664.110.
4
Can CVE-2021-4100 be exploited by a remote attacker?
Yes, CVE-2021-4100 can be exploited by a remote attacker via a specially crafted HTML page.
5
What component of Google Chrome does CVE-2021-4100 affect?
CVE-2021-4100 affects the ANGLE component of Google Chrome.