CVE-2021-30554 is a critical use-after-free vulnerability in WebGL affecting Google Chrome and Fedora Project's Chrome and Fedora, allowing remote attackers to achieve heap corruption via crafted HTML. With a CVSS score of 8.8 (HIGH), it is easily exploitable over the network with user interaction, potentially leading to high impact on confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has garnered significant community discussion and media coverage, despite no public exploit code being available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 91.0.4472.114CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.