EUVD-2021-17553
Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 3 Nov 2021. Evidence sources: cisa_kev.
- ENISA score
- 9.6 · CVSS 3.1
- Advisory evidence
- 8 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_opensuse · openSUSE-SU-2022:0110-1Security update for opera
- csaf_opensuse · openSUSE-SU-2022:0070-1Security update for nodejs-electron
- csaf_opensuse · openSUSE-SU-2021:1300-1Security update for chromium
- csaf_opensuse · openSUSE-SU-2021:1330-1Security update for opera
- csaf_opensuse · openSUSE-SU-2021:1303-1Security update for chromium
