CERT-In Vulnerability Note
CIVN-2021-0351
Multiple Vulnerabilities in Google Chrome
Original Issue Date:December 14, 2021
Severity Rating: HIGH
Software Affected
- Google Chrome version prior to 96.0.4664.110
Overview
Multiple vulnerabilities have been reported in Google Chrome which could be exploited by a remote attacker to execute arbitrary code on the targeted system.
Description
Multiple vulnerabilities exists in Google Chrome due to Insufficient data validation in Mojo , Use after free in Swiftshader and V8, Object lifecycle issue in ANGLE and Heap buffer overflow in Swiftshader. A remote attacker could exploit these vulnerabilities by enticing a victim to visit a specially crafted web page.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code on the targeted system.
Note: The vulnerability (CVE-2021-4102) is being actively exploited in the wild.
Solution
Apply appropriate security updates as mentioned in below link:
https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop_13.html
Vendor Information
Google Chrome
https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop_13.html
References
Google Chrome
https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop_13.html
Bleeping Computer
https://www.bleepingcomputer.com/news/security/google-pushes-emergency-chrome-update-to-fix-zero-day-used-in-attacks/
CVE Name
CVE-2021-4098
CVE-2021-4099
CVE-2021-4100
CVE-2021-4101
CVE-2021-4102
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|