CVE-2021-30633 is a critical use-after-free vulnerability in the Indexed DB API of Google Chrome, affecting versions prior to 93.0.4577.82, as well as Fedora Project's Chrome and Fedora. This flaw allows a remote attacker to potentially achieve sandbox escape via a crafted HTML page if they have already compromised the renderer process. With a CVSS score of 9.6 (CRITICAL), it presents a high-impact threat, enabling complete compromise of confidentiality, integrity, and availability with low attack complexity. The vulnerability is actively exploited in the wild, as indicated by its presence in the KEV catalog and extensive media coverage, despite a lack of publicly available exploit code on platforms like Metasploit or ExploitDB. Community discussion around this CVE is exceptionally high, reflecting significant attention to its active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 93.0.4577.82CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.