CVE-2021-30561
Published on: 08/03/2021 12:00:00 AM UTC
Last Modified on: 09/21/2021 04:16:00 PM UTC
Certain versions of Chrome from Google contain the following vulnerability:
Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-30561 has been assigned by
chrome-cve-a[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Google - Chrome version < 91.0.4472.164
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6.8 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Chrome Releases: Stable Channel Update for Desktop | chromereleases.googleblog.com text/html |
![]() |
Chrome JS WasmJs::InstallConditionalFeatures Object Corruption ≈ Packet Storm | packetstormsecurity.com text/html |
![]() |
1219630 - chromium - An open-source project to help move the web forward. - Monorail | crbug.com text/html |
![]() |
Related QID Numbers
- 180497 Debian Security Update for chromium (CVE-2021-30561)
- 281721 Fedora Security Update for chromium (FEDORA-2021-9f62d36f09)
- 281741 Fedora Security Update for chromium (FEDORA-2021-30c84b4924)
- 375718 Google Chrome Prior To 91.0.4472.164 Multiple Vulnerabilities
- 375737 Microsoft Edge Based On Chromium Prior to 91.0.864.71 Multiple Vulnerabilities
- 501819 Alpine Linux Security Update for chromium
- 710046 Gentoo Linux Chromium, Google Chrome Multiple Vulnerabilities (GLSA 202107-49)
- 750873 OpenSUSE Security Update for chromium (openSUSE-SU-2021:1073-1)
- 750926 OpenSUSE Security Update for opera (openSUSE-SU-2021:1096-1)
- 750932 OpenSUSE Security Update for opera (openSUSE-SU-2021:1095-1)
- 751978 OpenSUSE Security Update for opera (openSUSE-SU-2022:0110-1)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Chrome | All | All | All | All |
- cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Microsoft Edge (Chromium-based)に複数の脆弱性 Windows CVE-2021-30564 CVE-2021-30563 CVE-2021-30562 CVE-2021-30561 CVE-2021… twitter.com/i/web/status/1… | 2021-07-20 04:10:22 |
![]() |
CVE-2021-30561 : Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentia… twitter.com/i/web/status/1… | 2021-08-03 18:30:59 |