← לוח פגיעויות

CVE-2021-30633

קריטית 9.6 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Google Chromium Indexed DB API Use-After-Free Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

מדדים

CVSS 3.1
9.6 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS — סבירות ניצול
33% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-416

מוצרים מושפעים

google: chrome; fedoraproject: fedora

קישורים