Google has released Chrome 89.0.4389.90, which fixes five vulnerabilities, including the CVE-2021-21193 issue, already exploited by attackers in exploits (0-day). Details have not yet been disclosed, but it is known that the vulnerability is caused by accessing a freed memory area in the JavaScript engine Blink.
The issue has been assigned a high, but not critical, severity level, meaning that the vulnerability does not allow bypassing all levels of browser protection, and it is not sufficient to execute code on the system outside the sandbox environment. The vulnerability in Chrome itself does not allow bypassing the sandbox, and a full attack requires the exploitation of another vulnerability in the operating system.
Source: opennet.ru
