EXPOSURES › CVE-2021-30633
CVE-2021-30633
HIGH ⌖ ON CISA KEV · EXPLOITEDA use-after-free flaw in Chromium's Indexed DB API allowed sandbox escapes after a renderer compromise, but required prior compromise and was not a zero-day.
The vulnerability required an attacker to first compromise the renderer process before exploiting the use-after-free to escape the sandbox, meaning it was not a standalone remote code execution vector. DIB organizations should care because it highlights the risk of relying on browser sandboxing without additional hardening, and the fact it was added to KEV indicates active exploitation attempts. The primary mitigation is ensuring all Chromium-based browsers are patched to the latest version.
Shame score — The flaw was a known vulnerability that required a prior compromise to exploit, and it was not a zero-day or default-credential issue, resulting in moderate embarrassment.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
"Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker…perform a sandbox escape."
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |