Google Security Advisories · July 2021 — Google Security Advisories
173 advisories 95 CVEs 18 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2021-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 18 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2021-34448

GoogleExploitedCISA KEV listedHIGH2021-07-15

Scripting Engine Memory Corruption Vulnerability

CVEs:CVE-2021-34448

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_1909 affected microsoft
windows_10_2004 affected microsoft
windows_10_20h2 affected microsoft
windows_10_21h1 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
Upstream advisory

CVE-2021-30807

Project ZeroExploitedCISA KEV listed2021-07-27

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.

CVEs:CVE-2021-30807

Upstream advisory

CVE-2021-30807

GoogleExploitedCISA KEV listedCRITICAL2021-07-27

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware...

CVEs:CVE-2021-30807

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
watchos affected apple
Upstream advisory

openSUSE-SU-2021:1074-1

Open SourceExploitedCISA KEV listedCRITICAL2021-07-21

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

openSUSE-SU-2021:1073-1

Open SourceExploitedCISA KEV listedCRITICAL2021-07-21

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

CVE-2021-33771

GoogleExploitedCISA KEV listedCRITICAL2021-07-14

Windows Kernel Elevation of Privilege Vulnerability

CVEs:CVE-2021-33771

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_1909 affected microsoft
windows_10_2004 affected microsoft
windows_10_20h2 affected microsoft
windows_10_21h1 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2004 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_20h2 affected microsoft
Upstream advisory

CVE-2021-30563

GoogleExploitedCISA KEV listedHIGH2021-07-19

Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30563

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2021-30563

Project ZeroExploitedCISA KEV listed2021-07-19

Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30563

Upstream advisory

DEBIAN-CVE-2021-30554

Open SourceExploitedCISA KEV listedCRITICAL2021-07-02

DEBIAN-CVE-2021-30554

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-31979

GoogleExploitedCISA KEV listedCRITICAL2021-07-14

Windows Kernel Elevation of Privilege Vulnerability

CVEs:CVE-2021-31979

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_1909 affected microsoft
windows_10_2004 affected microsoft
windows_10_20h2 affected microsoft
windows_10_21h1 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2004 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_20h2 affected microsoft
Upstream advisory

CVE-2021-25740

Open SourceActive exploitation (sightings)LOW2021-07-14

A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

CVEs:CVE-2021-25740

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
kubernetes affected kubernetes
Kubernetes affected Kubernetes
Upstream advisory

CVE-2021-25740

Open SourceActive exploitation (sightings)LOW2021-07-14

Confused Deputy in Kubernetes

CVEs:CVE-2021-25740

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2021-30560

GooglePoC exploitHIGH2021-07-19

Nokogiri has vulnerable dependencies on libxml2 and libxslt

CVEs:CVE-2021-30560

Affected products

ProductStatusVendorPackageEcosystem
nokogiri affected RubyGems nokogiri
Upstream advisory

CVE-2021-30560

GooglePoC exploitCRITICAL2021-07-19

Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30560

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
libxslt affected xmlsoft
universal_forwarder affected splunk
Upstream advisory

MGASA-2021-0369

Open SourcePoC exploitHIGH2021-07-25

Updated golang packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:8 golang
Upstream advisory

CVE-2021-34558

GooglePoC exploitHIGH2021-07-15

The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.

CVEs:CVE-2021-34558

Affected products

ProductStatusVendorPackageEcosystem
cloud_insights_telegraf affected netapp
fedora affected fedoraproject
go affected golang
storagegrid affected netapp
timesten_in-memory_database affected oracle
trident affected netapp
Upstream advisory

DEBIAN-CVE-2021-34558

Open SourcePoC exploitHIGH2021-07-15

DEBIAN-CVE-2021-34558

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

CVE-2021-30573

GooglePoC exploitCRITICAL2021-07-21

Use after free in GPU in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30573

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

PUB-A-177123726

GooglePoC exploit2021-07-01

PUB-A-177123726

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

DEBIAN-CVE-2021-23409

Open SourcePoC exploitHIGH2021-07-21

DEBIAN-CVE-2021-23409

Affected products

ProductStatusVendorPackageEcosystem
golang-github-pires-go-proxyproto affected Debian:11 golang-github-pires-go-proxyproto
golang-github-pires-go-proxyproto affected Debian:12 golang-github-pires-go-proxyproto
golang-github-pires-go-proxyproto affected Debian:13 golang-github-pires-go-proxyproto
golang-github-pires-go-proxyproto affected Debian:14 golang-github-pires-go-proxyproto
Upstream advisory

CVE-2021-0515

Open SourcePoC exploitHIGH2021-07-14

In Factory::CreateStrictFunctionMap of factory.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User intera...

CVEs:CVE-2021-0515

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-167389063

Open SourcePoC exploitHIGH2021-07-01

ASB-A-167389063

Affected products

ProductStatusVendorPackageEcosystem
external/chromium-libpac affected platform platform/external/chromium-libpac
external/v8 affected platform platform/external/v8
Upstream advisory

CVE-2021-0594

Open SourcePoC exploitHIGH2021-07-14

In onCreate of ConfirmConnectActivity, there is a possible remote bypass of user consent due to improper input validation. This could lead to remote (proximal, NFC) escalation of privilege allowing an attacker to deceive a user into allowing a Bluetoot...

CVEs:CVE-2021-0594

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0596

Open SourcePoC exploitHIGH2021-07-14

In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over NFC with no additional execution privileges needed. User interaction is not ...

CVEs:CVE-2021-0596

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0514

Open SourcePoC exploitHIGH2021-07-14

In several functions of the V8 library, there is a possible use after free due to a race condition. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2021-0514

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-162604069

Open SourcePoC exploitHIGH2021-07-01

ASB-A-162604069

Affected products

ProductStatusVendorPackageEcosystem
external/chromium-libpac affected platform platform/external/chromium-libpac
external/v8 affected platform platform/external/v8
Upstream advisory

CVE-2021-0592

Open SourcePoC exploitHIGH2021-07-14

In various functions in WideVine, there are possible out of bounds writes due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: An...

CVEs:CVE-2021-0592

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-188061006

GooglePoC exploitHIGH2021-07-01

ASB-A-188061006

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-185462528

GooglePoC exploit2021-07-01

PUB-A-185462528

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-183840808

GooglePoC exploitMEDIUM2021-07-01

PUB-A-183840808

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-183840542

GooglePoC exploit2021-07-01

PUB-A-183840542

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-0600

Open SourcePoC exploitHIGH2021-07-14

In onCreate of DeviceAdminAdd.java, there is a possible way to mislead a user to activate a device admin app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...

CVEs:CVE-2021-0600

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0586

Open SourcePoC exploitHIGH2021-07-14

In onCreate of DevicePickerFragment.java, there is a possible way to trick the user to select an unwanted bluetooth device due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges need...

CVEs:CVE-2021-0586

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0589

Open SourcePoC exploitHIGH2021-07-14

In BTM_TryAllocateSCN of btm_scn.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2021-0589

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-184561360

GooglePoC exploit2021-07-01

ASB-A-184561360

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2021-0604

Open SourcePoC exploitMEDIUM2021-07-14

In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible way to share private files over Bluetooth due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interacti...

CVEs:CVE-2021-0604

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0587

Open SourcePoC exploitHIGH2021-07-14

In StreamOut::prepareForWriting of StreamOut.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2021-0587

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0577

Open SourcePoC exploitHIGH2021-07-14

In flv extractor, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...

CVEs:CVE-2021-0577

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0417

Open SourcePoC exploitHIGH2021-07-14

In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2020-0417

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-187161771

GooglePoC exploitHIGH2021-07-01

ASB-A-187161771

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0585

Open SourcePoC exploitHIGH2021-07-14

In beginWrite and beginRead of MessageQueueBase.h, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2021-0585

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0588

Open SourcePoC exploitMEDIUM2021-07-14

In processInboundMessage of MceStateMachine.java, there is a possible SMS disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2021-0588

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0599

Open SourcePoC exploitMEDIUM2021-07-14

In scheduleTimeoutLocked of NotificationRecord.java, there is a possible disclosure of a sensitive identifier via broadcasted intent due to a confused deputy. This could lead to local information disclosure with no additional execution privileges neede...

CVEs:CVE-2021-0599

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0601

Open SourcePoC exploitHIGH2021-07-14

In encodeFrames of avc_enc_fuzzer.cpp, there is a possible out of bounds write due to a double free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2021-0601

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0597

Open SourcePoC exploitMEDIUM2021-07-14

In notifyProfileAdded and notifyProfileRemoved of SipService.java, there is a possible way to retrieve SIP account names due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. ...

CVEs:CVE-2021-0597

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2021-30557

Open SourceCoalition ESS < 30%CRITICAL2021-07-02

DEBIAN-CVE-2021-30557

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30582

GoogleCoalition ESS < 30%MEDIUM2021-07-21

Inappropriate implementation in Animation in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2021-30582

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30561

GoogleCoalition ESS < 30%HIGH2021-07-19

Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30561

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2021-36929

Open SourceCoalition ESS < 30%HIGH2021-07-23

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

CVEs:CVE-2021-36929

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2021-36153

Open SourceCoalition ESS < 30%HIGH2021-07-09

Mismanaged state in GRPCWebToHTTP2ServerCodec.swift in gRPC Swift 1.1.0 and 1.1.1 allows remote attackers to deny service by sending malformed requests.

CVEs:CVE-2021-36153

Affected products

ProductStatusVendorPackageEcosystem
grpc_swift affected linuxfoundation
Upstream advisory

CVE-2021-36153

Open SourceCoalition ESS < 30%HIGH2021-07-09

Incomplete Internal State Distinction in GRPCWebToHTTP2ServerCodec

CVEs:CVE-2021-36153

Affected products

ProductStatusVendorPackageEcosystem
grpc/grpc-swift affected github.com github.com/grpc/grpc-swift
Upstream advisory

CVE-2021-36154

Open SourceCoalition ESS < 30%HIGH2021-07-09

HTTP2ToRawGRPCServerCodec in gRPC Swift 1.1.1 and earlier allows remote attackers to deny service via the delivery of many small messages within a single HTTP/2 frame, leading to Uncontrolled Recursion and stack consumption.

CVEs:CVE-2021-36154

Affected products

ProductStatusVendorPackageEcosystem
grpc_swift affected linuxfoundation
Upstream advisory

CVE-2021-36154

Open SourceCoalition ESS < 30%2021-07-09

Uncontrolled Recursion in HTTP2ToRawGRPCServerCodec

CVEs:CVE-2021-36154

Affected products

ProductStatusVendorPackageEcosystem
grpc/grpc-swift affected github.com github.com/grpc/grpc-swift
Upstream advisory

CVE-2021-36155

Open SourceCoalition ESS < 30%CRITICAL2021-07-09

LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote attackers to cause uncontrolled resource consumption and deny service.

CVEs:CVE-2021-36155

Affected products

ProductStatusVendorPackageEcosystem
grpc_swift affected linuxfoundation
Upstream advisory

CVE-2021-36155

Open SourceCoalition ESS < 30%HIGH2021-07-09

Uncontrolled Resource Consumption in LengthPrefixedMessageReader

CVEs:CVE-2021-36155

Affected products

ProductStatusVendorPackageEcosystem
grpc/grpc-swift affected github.com github.com/grpc/grpc-swift
Upstream advisory

CVE-2021-30588

GoogleCoalition ESS < 30%HIGH2021-07-21

Type confusion in V8 in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30588

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30584

GoogleCoalition ESS < 30%MEDIUM2021-07-21

Incorrect security UI in Downloads in Google Chrome on Android prior to 92.0.4515.107 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVEs:CVE-2021-30584

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30565

GoogleCoalition ESS < 30%CRITICAL2021-07-21

Out of bounds write in Tab Groups in Google Chrome on Linux and ChromeOS prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.

CVEs:CVE-2021-30565

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30583

GoogleCoalition ESS < 30%CRITICAL2021-07-21

Insufficient policy enforcement in image handling in iOS in Google Chrome on iOS prior to 92.0.4515.107 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2021-30583

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30556

Open SourceCoalition ESS < 30%CRITICAL2021-07-02

DEBIAN-CVE-2021-30556

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30578

GoogleCoalition ESS < 30%HIGH2021-07-21

Uninitialized use in Media in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.

CVEs:CVE-2021-30578

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30566

GoogleCoalition ESS < 30%CRITICAL2021-07-21

Stack buffer overflow in Printing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to potentially exploit stack corruption via a crafted HTML page.

CVEs:CVE-2021-30566

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30541

GoogleCoalition ESS < 30%CRITICAL2021-07-19

Use after free in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30541

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2021-30587

GoogleCoalition ESS < 30%MEDIUM2021-07-21

Inappropriate implementation in Compositing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2021-30587

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30574

GoogleCoalition ESS < 30%CRITICAL2021-07-21

Use after free in protocol handling in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30574

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30575

GoogleCoalition ESS < 30%CRITICAL2021-07-21

Out of bounds write in Autofill in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30575

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30572

GoogleCoalition ESS < 30%CRITICAL2021-07-21

Use after free in Autofill in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30572

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30579

GoogleCoalition ESS < 30%CRITICAL2021-07-21

Use after free in UI framework in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30579

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30589

GoogleCoalition ESS < 30%MEDIUM2021-07-21

Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to bypass navigation restrictions via a crafted click-to-call link.

CVEs:CVE-2021-30589

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30568

GoogleCoalition ESS < 30%CRITICAL2021-07-21

Heap buffer overflow in WebGL in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30568

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30564

GoogleCoalition ESS < 30%CRITICAL2021-07-19

Heap buffer overflow in WebXR in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30564

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2021-30569

GoogleCoalition ESS < 30%CRITICAL2021-07-21

Use after free in sqlite in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30569

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30585

GoogleCoalition ESS < 30%CRITICAL2021-07-21

Use after free in sensor handling in Google Chrome on Windows prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30585

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30555

Open SourceCoalition ESS < 30%CRITICAL2021-07-02

DEBIAN-CVE-2021-30555

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30580

GoogleCoalition ESS < 30%CRITICAL2021-07-21

Insufficient policy enforcement in Android intents in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious application to obtain potentially sensitive information via a crafted HTML page.

CVEs:CVE-2021-30580

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30559

GoogleCoalition ESS < 30%CRITICAL2021-07-19

Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30559

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2021-30562

GoogleCoalition ESS < 30%CRITICAL2021-07-19

Use after free in WebSerial in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30562

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2021-36931

Open SourceCoalition ESS < 30%CRITICAL2021-07-23

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2021-36931

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2021-30576

GoogleCoalition ESS < 30%CRITICAL2021-07-21

Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30576

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30581

GoogleCoalition ESS < 30%CRITICAL2021-07-21

Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30581

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30571

GoogleCoalition ESS < 30%CRITICAL2021-07-21

Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-30571

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30567

GoogleCoalition ESS < 30%CRITICAL2021-07-21

Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to open DevTools to potentially exploit heap corruption via specific user gesture.

CVEs:CVE-2021-30567

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30586

GoogleCoalition ESS < 30%CRITICAL2021-07-21

Use after free in dialog box handling in Windows in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30586

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30577

GoogleCoalition ESS < 30%HIGH2021-07-21

Insufficient policy enforcement in Installer in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform local privilege escalation via a crafted file.

CVEs:CVE-2021-30577

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-36928

Open SourceCoalition ESS < 30%CRITICAL2021-07-23

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2021-36928

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

PUB-A-183694099

GoogleCoalition ESS < 30%2021-07-01

PUB-A-183694099

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-25426

Open SourceCoalition ESS < 30%HIGH2021-07-08

Improper component protection vulnerability in SmsViewerActivity of Samsung Message prior to SMR July-2021 Release 1 allows untrusted applications to access Message files.

CVEs:CVE-2021-25426

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0654

Open SourceCoalition ESS < 30%MEDIUM2021-07-14

In isRealSnapshot of TaskThumbnailView.java, there is possible data exposure due to a missing permission check. This could lead to local information disclosure from locked profiles with no additional execution privileges needed. User interaction is nee...

CVEs:CVE-2021-0654

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-168802517

GoogleCoalition ESS < 30%MEDIUM2021-07-01

PUB-A-168802517

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-25427

Open SourceCoalition ESS < 30%CRITICAL2021-07-08

SQL injection vulnerability in Bluetooth prior to SMR July-2021 Release 1 allows unauthorized access to paired device information

CVEs:CVE-2021-25427

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25429

Open SourceCoalition ESS < 30%MEDIUM2021-07-08

Improper privilege management vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.

CVEs:CVE-2021-25429

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25430

Open SourceCoalition ESS < 30%MEDIUM2021-07-08

Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.

CVEs:CVE-2021-25430

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0602

Open SourceCoalition ESS < 30%HIGH2021-07-14

In onCreateOptionsMenu of WifiNetworkDetailsFragment.java, there is a possible way for guest users to view and modify Wi-Fi settings for all configured APs due to a permissions bypass. This could lead to local escalation of privilege with no additional...

CVEs:CVE-2021-0602

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0590

Open SourceCoalition ESS < 30%MEDIUM2021-07-14

In sendNetworkConditionsBroadcast of NetworkMonitor.java, there is a possible way for a privileged app to receive WiFi BSSID and SSID without location permissions due to a missing permission check. This could lead to local information disclosure with S...

CVEs:CVE-2021-0590

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0603

Open SourceCoalition ESS < 30%HIGH2021-07-14

In onCreate of ContactSelectionActivity.java, there is a possible way to get access to contacts without permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interact...

CVEs:CVE-2021-0603

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0518

Open SourceCoalition ESS < 30%MEDIUM2021-07-14

In Wi-Fi, there is a possible leak of location-sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An...

CVEs:CVE-2021-0518

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0441

Open SourceCoalition ESS < 30%HIGH2021-07-14

In onCreate of PermissionActivity.java, there is a possible permission bypass due to Confusing UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: And...

CVEs:CVE-2021-0441

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0486

Open SourceCoalition ESS < 30%HIGH2021-07-14

In onPackageAddedInternal of PermissionManagerService.java, there is possible access to external storage due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed...

CVEs:CVE-2021-0486

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25428

Open SourceCoalition ESS < 30%HIGH2021-07-08

Improper validation check vulnerability in PackageManager prior to SMR July-2021 Release 1 allows untrusted applications to get dangerous level permission without user confirmation in limited circumstances.

CVEs:CVE-2021-25428

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2012-2666

GoogleEPSS <= 49%CRITICAL2021-07-09

golang/go in 1.0.2 fixes all.bash on shared machines. dotest() in src/pkg/debug/gosym/pclntab_test.go creates a temporary file with predicable name and executes it as shell script.

CVEs:CVE-2012-2666

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

OSV-2021-1074

Open SourceAll remainingHIGH2021-07-30

Use-of-uninitialized-value in SkBaseDevice::save

Affected products

ProductStatusVendorPackageEcosystem
skia affected OSS-Fuzz skia
Upstream advisory

OSV-2021-1071

Open SourceAll remainingCRITICAL2021-07-30

Heap-use-after-free in SkCanvas::MCRec::MCRec

Affected products

ProductStatusVendorPackageEcosystem
skia affected OSS-Fuzz skia
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.