CVE-2021-30547:Out of bounds write vulnerability in ANGLE component of Google Chrome

splash
Back

Description Preview

CVE-2021-30547 is an out of bounds write vulnerability (CWE-787) in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. This vulnerability affects versions prior to 91.0.4472.101. An attacker could exploit this vulnerability by crafting a malicious HTML page that, when processed by the vulnerable ANGLE component, could lead to out of bounds memory access. This could potentially allow the attacker to execute arbitrary code within the context of the browser or cause a denial of service condition.

Overview

ANGLE (Almost Native Graphics Layer Engine) is a graphics engine abstraction layer used by Google Chrome to handle OpenGL ES API calls. The vulnerability exists due to improper validation of input data, which can lead to memory corruption through an out of bounds write operation. When exploited, this vulnerability could allow remote attackers to execute arbitrary code within the context of the browser, potentially leading to full system compromise depending on the user's privileges. The vulnerability is particularly concerning because it can be triggered simply by visiting a malicious or compromised website.

Remediation

Users should update Google Chrome to version 91.0.4472.101 or later, which contains the fix for this vulnerability. The update can be installed through Chrome's built-in update mechanism or by downloading the latest version from the official Google Chrome website.

For system administrators managing Chrome deployments:

  1. Ensure all Chrome installations are updated to version 91.0.4472.101 or later
  2. Consider implementing network security monitoring to detect exploitation attempts
  3. Apply defense-in-depth strategies such as running the browser with reduced privileges
  4. Consider using browser isolation technologies for high-risk environments

For users of other browsers that incorporate ANGLE or Chromium components (such as Microsoft Edge, Opera, etc.), ensure these browsers are also updated to versions that include the patched ANGLE component.

References

  1. Chrome Release Blog: https://chromereleases.googleblog.com/2021/06/stable-channel-update-for-desktop.html
  2. Chrome Bug Tracker: https://crbug.com/1210414
  3. Debian Security Advisory: https://www.debian.org/security/2021/dsa-4939
  4. Debian LTS Announcement: https://lists.debian.org/debian-lts-announce/2021/07/msg00009.html
  5. Fedora Update: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ETMZL6IHCTCTREEL434BQ4THQ7EOHJ43/
  6. Gentoo Linux Security Advisory: https://security.gentoo.org/glsa/202202-03
  7. Thunderbird Security Update: https://lists.debian.org/debian-lts-announce/2021/07/msg00010.html

Industry ExposureMost to least
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.

  1. Health Care & Social Assistance
    Health Care & Social Assistance
  2. Manufacturing
    Manufacturing
  3. Public Administration
    Public Administration
  4. Educational Services
    Educational Services
  5. Finance and Insurance
    Finance and Insurance
  6. Transportation & Warehousing
    Transportation & Warehousing
  7. Professional, Scientific, & Technical Services
    Professional, Scientific, & Technical Services
  8. Utilities
    Utilities
  9. Retail Trade
    Retail Trade
  10. Other Services (except Public Administration)
    Other Services (except Public Administration)
  11. Arts, Entertainment & Recreation
    Arts, Entertainment & Recreation
  12. Information
    Information
  13. Management of Companies & Enterprises
    Management of Companies & Enterprises
  14. Agriculture, Forestry Fishing & Hunting
    Agriculture, Forestry Fishing & Hunting
  15. Real Estate Rental & Leasing
    Real Estate Rental & Leasing
  16. Accommodation & Food Services
    Accommodation & Food Services
  17. Construction
    Construction
  18. Mining
    Mining
  19. Administrative, Support, Waste Management & Remediation Services
    Administrative, Support, Waste Management & Remediation Services
  20. Wholesale Trade
    Wholesale Trade

Focus on What Matters

  1. See Everything.
  2. Identify True Risk.
  3. Proactively Mitigate Threats.

Let's talk!

background