CVE-2021-30508 describes a heap buffer overflow in Google Chrome's Media Feeds, affecting versions prior to 90.0.4430.212, as well as Fedora Project's Chrome and Fedora. This vulnerability carries a high CVSS score of 8.8, indicating a critical risk where an unauthenticated attacker could achieve high impact on confidentiality, integrity, and availability if a user is convinced to enable specific Chrome features via a crafted HTML page. While there is no evidence of active exploitation (not in KEV), and no public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 90.0.4430.212CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.