Google has released Chrome 93.0.4577.82, which fixes 11 vulnerabilities, including two issues already being exploited by attackers in 0-day exploits. Details have not yet been disclosed, but it is known that the first vulnerability (CVE-2021-30632) is caused by a buffer overflow error in the V8 JavaScript engine, and the second issue (CVE-2021-30633) exists in the implementation of the Indexed DB API and is related to accessing memory after it has been freed (use-after-free).
Among the other vulnerabilities are two issues caused by accessing memory after it has been freed in the Selection and Permissions APIs; type confusion in the Blink engine; and buffer overflows in the ANGLE (Almost Native Graphics Layer Engine) layer. All vulnerabilities have been classified as dangerous. No critical issues have been found that would allow bypassing all layers of the browser's protection and executing code on the system outside the sandbox environment.
Source: opennet.ru
