Skip to content
COOEY

EXPOSURES › CVE-2021-30633

CVE-2021-30633

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-30633 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatched

A use-after-free flaw in Chromium's Indexed DB API allowed sandbox escapes after a renderer compromise, but required prior compromise and was not a zero-day.

The vulnerability required an attacker to first compromise the renderer process before exploiting the use-after-free to escape the sandbox, meaning it was not a standalone remote code execution vector. DIB organizations should care because it highlights the risk of relying on browser sandboxing without additional hardening, and the fact it was added to KEV indicates active exploitation attempts. The primary mitigation is ensuring all Chromium-based browsers are patched to the latest version.

Shame score — The flaw was a known vulnerability that required a prior compromise to exploit, and it was not a zero-day or default-credential issue, resulting in moderate embarrassment.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

SENTIMENT · TRUSTED SOURCES
synthesis negative -0.60
Acknowledged vulnerability with potential for serious impact.
cooey ↗ negative -0.70
Describes a serious vulnerability with broad impact.
"Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker…perform a sandbox escape."
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized