Description Preview
Overview
The vulnerability is classified as CWE-843 (Access of Resource Using Incompatible Type), specifically a type confusion issue in the V8 JavaScript engine. Type confusion vulnerabilities occur when a program accesses a resource using an incompatible type, which can lead to out-of-bounds memory access or other memory corruption issues. In this case, the vulnerability allows attackers to execute arbitrary code within the Chrome sandbox environment by crafting malicious HTML pages that trigger the type confusion condition. The vulnerability affects all Chrome versions prior to 90.0.4430.85 across multiple platforms including Windows, macOS, and Linux.
Remediation
To mitigate this vulnerability, users should update Google Chrome to version 90.0.4430.85 or later. The update can be applied by:
- Opening Chrome and clicking on the three dots in the upper right corner
- Selecting "Help" > "About Google Chrome"
- Chrome will automatically check for updates and install them if available
- Restart the browser after the update is installed
System administrators should ensure that all Chrome installations in their environment are updated to the patched version. For Fedora users, updates are available through the package manager as indicated in the referenced advisories. Debian users should apply the security update referenced in DSA-4906.
References
- Chrome Release Blog: https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_20.html
- Chrome Bug Tracker: https://crbug.com/1195777
- Fedora Security Advisory: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EAJ42L4JFPBJATCZ7MOZQTUDGV4OEHHG/
- Fedora Security Advisory: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U3GZ42MYPGD35V652ZPVPYYS7A7LVXVY/
- Fedora Security Advisory: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VUZBGKGVZADNA3I24NVG7HAYYUTOSN5A/
- Gentoo Security Advisory: https://security.gentoo.org/glsa/202104-08
- Debian Security Advisory: https://www.debian.org/security/2021/dsa-4906
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- Health Care & Social AssistanceHealth Care & Social Assistance
- ManufacturingManufacturing
- Educational ServicesEducational Services
- Public AdministrationPublic Administration
- Transportation & WarehousingTransportation & Warehousing
- Finance and InsuranceFinance and Insurance
- Retail TradeRetail Trade
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- Other Services (except Public Administration)Other Services (except Public Administration)
- UtilitiesUtilities
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- InformationInformation
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- ConstructionConstruction
- MiningMining
- Real Estate Rental & LeasingReal Estate Rental & Leasing
- Accommodation & Food ServicesAccommodation & Food Services
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- Wholesale TradeWholesale Trade
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services