CVE-2021-30628 is a high-severity stack buffer overflow vulnerability in ANGLE, affecting Google Chrome and Fedora Project's Chrome and Fedora prior to version 93.0.4577.82. This flaw allows a remote attacker to potentially corrupt the stack and achieve high impact to confidentiality, integrity, and availability through a crafted HTML page, requiring user interaction. While not listed in CISA's KEV catalog, it was reportedly exploited as a zero-day, with one article confirming active exploitation. There are no public exploit modules or significant community discussion beyond this report.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 93.0.4577.82CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.