Google releases Chrome 93 security update (93.0.4577.82) with fixes for 2 zero-days under attack

Google releases Chrome 93 security update (93.0.4577.82) with fixes for 2 zero-days under attack

Google has released Chrome 93 security update (93.0.4577.82) with fixes for 2 zero-day vulnerabilities under attack.

An attacker could exploit these vulnerabilities to take control of impacted systems.

The Chrome 93 security update patched 11 vulnerabilities in all, 9 of those rated High severity and discovered by external researchers (bold with active exploits):

  1. CVE-2021-30625: Use after free in Selection API.
  2. CVE-2021-30626: Out of bounds memory access in ANGLE.
  3. CVE-2021-30627: Type Confusion in Blink layout.
  4. CVE-2021-30628: Stack buffer overflow in ANGLE.
  5. CVE-2021-30629: Use after free in Permissions.
  6. CVE-2021-30630: Inappropriate implementation in Blink .
  7. CVE-2021-30631: Type Confusion in Blink layout.
  8. CVE-2021-30632: Out of bounds write in V8.
  9. CVE-2021-30633: Use after free in Indexed DB API

Google warned it “is aware that exploits for CVE-2021-30632 and CVE-2021-30633 exist in the wild.”

Finally, Google also released Chrome 93 (93.0.4577.82) for Android and Chrome 93 (93.0.4577.78) for iOS.

Related Articles