Vulnerability CVE-2021-30625: Information

Description

Use after free in Selection API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who convinced the user the visit a malicious website to potentially exploit heap corruption via a crafted HTML page.

Severity: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: Oct. 9, 2021
Modified: Nov. 7, 2023
Error type identifier: CWE-416

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
chromiumsisyphus93.0.4577.82-alt1124.0.6367.78-alt1ALT-PU-2021-2799-1285223Fixed
chromiump1093.0.4577.82-alt1119.0.6045.159-alt0.p10.1ALT-PU-2021-2843-1285356Fixed
chromiump994.0.4606.81-alt0.p9.197.0.4692.99-alt0.p9.1ALT-PU-2021-3044-1285873Fixed
chromiumc10f193.0.4577.82-alt1110.0.5481.177-alt1.p10.1ALT-PU-2021-2843-1285356Fixed
chromium-gostsisyphus94.0.4606.71-alt1124.0.6367.78-alt1ALT-PU-2021-2987-1286559Fixed
chromium-gostp1094.0.4606.71-alt2110.0.5481.177-alt1.p10.1ALT-PU-2021-3050-1286785Fixed
chromium-gostp996.0.4664.45-alt2.p9.196.0.4664.45-alt2.p9.1ALT-PU-2021-3603-1291751Fixed
chromium-gostc10f194.0.4606.71-alt2110.0.5481.177-alt1.p10.1ALT-PU-2021-3050-1286785Fixed
chromium-gostc9f296.0.4664.45-alt2.c9.196.0.4664.45-alt2.c9.1ALT-PU-2021-3436-1284092Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
      End excliding
      93.0.4577.82

      Configuration 2

      cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*