Chrome update 93.0.4577.82 fixing 0-day vulnerabilities

Google has released Chrome update 93.0.4577.82, which fixes 11 vulnerabilities, including two problems already used by attackers in exploits (0-day). Details have not yet been disclosed, it is only known that the first vulnerability (CVE-2021-30632) is caused by a bug that leads to writing out of buffer bounds in the V8 JavaScript engine, and the second problem (CVE-2021-30633) is present in the implementation of the Indexed DB API and associated with accessing a memory area after it is freed (use-after-free).

Other vulnerabilities include: two post-free memory access issues in the Selection and Permissions APIs; incorrect handling of types (Type Confusion) in the Blink engine; buffer overflows in the ANGLE (Almost Native Graphics Layer Engine) layer. All vulnerabilities have received the dangerous status. There were no critical issues that individually allow bypassing all browser protection levels and executing code in the system outside the sandbox environment.

Source: opennet.ru

Add a comment