CERT-In Vulnerability Note 
                                                                      CIVN-2021-0351 
                                                                      Multiple Vulnerabilities in Google Chrome
                                                                      Original Issue Date:December  14, 2021 
                                                                      
                                                                           
                                                                        Severity Rating: HIGH 
																		
																		
																		
																		
																		
																		
	                                                                      Software Affected  
           	                                                          
																	  
                                                                          - Google Chrome version prior to 96.0.4664.110
  
																	
                                                                      
																	  
																	   
																	     
																	   
																	   
                                                                      Overview  
                                                                      Multiple vulnerabilities have been reported in Google Chrome which could be exploited by a remote attacker to execute arbitrary code on the targeted system.
                                                                      
										
								       Description 
										
 
                                            Multiple vulnerabilities exists in Google Chrome due to Insufficient data validation in Mojo , Use after free in Swiftshader and V8, Object lifecycle issue in ANGLE and Heap buffer overflow in Swiftshader.  A remote attacker could exploit these vulnerabilities by enticing a victim to visit a specially crafted web page.
  Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code on the targeted system.
                                           
                                            
                                            
                                            	
                                            
                                           
										   
										  	  	 Note: The vulnerability (CVE-2021-4102) is being actively exploited in the wild.
										   	
  
										   
															                              
															      
										
								       Solution 
										
                                            Apply appropriate security updates as mentioned in below link: 
                                            
													 
													
                                                    
												https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop_13.html  
																					                                                                    
												 
												
												
												
										   	
										   
										
								       Vendor Information 
										
                                            Google Chrome 
                                            
                                                    
												https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop_13.html  
																					                                                                    
												 
												 
												
												
										   	 
										   
          
										
								       References 
										
                                             
                                            Google Chrome 
                                            
    	                                        
                                                    
													
													https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop_13.html  
																					                                                                    
												 
												
											
												
										   	 
										   
                                             
                                            Bleeping Computer 
                                            
    	                                        
                                                    
													
													https://www.bleepingcomputer.com/news/security/google-pushes-emergency-chrome-update-to-fix-zero-day-used-in-attacks/   
																					                                                                    
												 
												
											
												
										   	 
										   
										
										CVE Name 
										
                                                    
												CVE-2021-4098 
																					                                                                    
												 
												
												
                                                    
												CVE-2021-4099 
																					                                                                    
												 
												
												
                                                    
												CVE-2021-4100 
																					                                                                    
												 
												
												
                                                    
												CVE-2021-4101 
																					                                                                    
												 
												
												
                                                    
												CVE-2021-4102 
																					                                                                    
												 
												
												
	                                     
           
										
	                                    
													
                                                          Disclaimer 
                                                          The information provided herein is on "as is" basis, without warranty of any kind.  
                                                    
                          
                                           
													
                                                      Contact Information  
                                                      Email: info@cert-in.org.in  Phone: +91-11-24368572 
                                                    
													
                                                                      Postal address  
                                                                      Indian Computer Emergency Response Team (CERT-In)  Ministry of Electronics and Information Technology Government of India  Electronics Niketan  6, CGO Complex, Lodhi Road,  New Delhi - 110 003  India 
                                                    
                                                                    
                                                                       
                                                                       |