Google has released an update for Chrome 96.0.4664.110, which fixes 5 vulnerabilities, including a vulnerability (CVE-2021-4102) already being exploited by attackers in 0-day exploits and a critical vulnerability (CVE-2021-4098) that allows bypassing all levels of browser protection and executing code in the system outside of the sandbox environment.
Details are not yet disclosed, but it is known that the 0-day vulnerability is caused by a use-after-free memory issue in the V8 engine, while the critical vulnerability is related to insufficient data validation in the IPC framework Mojo. Other vulnerabilities mentioned include a buffer overflow (CVE-2021-4101) and a use-after-free memory access (CVE-2021-4099) in the Swiftshader rendering system, as well as an issue (CVE-2021-4100) with object lifecycle management in ANGLE, a translation layer for OpenGL ES calls to OpenGL, Direct3D 9/11, Desktop GL, and Vulkan.
Source: opennet.ru
