Vulnerabilities > CVE-2021-21207 - Use After Free vulnerability in multiple products

047910
CVSS 8.6 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH

Summary

Use after free in IndexedDB in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

Vulnerable Configurations

Part Description Count
Application
Google
5650
OS
Debian
1
OS
Fedoraproject
3

Common Weakness Enumeration (CWE)