18 June 2021

Google fixes yet another Chrome 0Day exploited in the wild


Google fixes yet another Chrome 0Day exploited in the wild

Google has released Chrome 91.0.4472.114 for Windows, Mac, and Linux designed to address four security vulnerabilities, including a zero-day bug exploited in the wild.

The zero-day vulnerability, tracked as CVE-2021-30554, is described as a use-after-free issue residing within the WebGL component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system. Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.

In accordance with its security policy, Google refrained from publishing details of the vulnerability until the majority of users update their Chrome browsers.

Chrome users can update their browsers to the latest version by heading to Settings > Help > 'About Google Chrome'.

In addition to CVE-2021-30554, Chrome 91.0.4472.114 resolves three high-risk vulnerabilities affecting Sharing, WebAudio, and TabGroups components in Chrome (CVE-2021-30555, CVE-2021-30556, CVE-2021-30557). All three bugs are use-after-three issues that allow a remote attacker to compromise a vulnerable system.

The new security update comes just a week after Google released the Chrome 91.0.4472.101 version that addressed 14 security vulnerabilities, including a zero-day flaw in V8 component said to be exploited in the wild.


Back to the list

Latest Posts

OpenJS Foundation reports attempted supply-chain attacks on JavaScript projects

OpenJS Foundation reports attempted supply-chain attacks on JavaScript projects

The attackers attempted to introduce suspicious updates or asked to be made maintainers of the targeted software.
17 April 2024
Multiple botnets are hunting for vulnerable TP-Link routers

Multiple botnets are hunting for vulnerable TP-Link routers

Cybersecurity researchers have observed a surge in attacks targeting CVE-2023-1389.
17 April 2024
Cisco warns of large-scale brute-force attacks targeting VPNs, SSH services

Cisco warns of large-scale brute-force attacks targeting VPNs, SSH services

The consequences of a successful attack can range from unauthorized network access and account lockouts to denial-of-service conditions.
17 April 2024