Skip to content
COOEY

EXPOSURES › CVE-2021-30554

CVE-2021-30554

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-30554 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 exploited-in-wildunpatchedrce

A use-after-free vulnerability in Google Chromium WebGL allowed remote attackers to exploit heap corruption via a crafted HTML page, affecting multiple Chromium-based browsers.

This vulnerability was actively exploited in the wild (KEV) and could lead to remote code execution, posing a significant risk to systems relying on Chromium browsers. DIB organizations must ensure their browsers are patched promptly to prevent exploitation and maintain compliance with security requirements. The failure highlights the importance of timely patch management and monitoring for actively exploited vulnerabilities.

Shame score — The vulnerability was actively exploited in the wild and affected multiple widely used browsers, indicating a significant security lapse that could have been mitigated with timely patching.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium WebGL contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

SENTIMENT · TRUSTED SOURCES
synthesis negative -0.40
Acknowledged vulnerability, potential for broad impact.
cooey ↗ negative -0.40
Describes the vulnerability and its potential impact.
"Google Chromium WebGL contains a use-after-free vulnerability..."
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized