Описание
Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
A flaw was found in Google Chrome on Android. This vulnerability, a use-after-free error in the WebGL component, could be exploited by a remote attacker. After compromising the renderer process, the attacker could craft a malicious HTML page to trigger the flaw. This could potentially lead to a sandbox escape, allowing the attacker to gain elevated privileges or further control over the system.
Отчет
This Important vulnerability in WebGL within Chromium allows a remote attacker, after compromising the renderer process, to perform a sandbox escape via a crafted HTML page. This flaw, while initially reported for Android, affects Chromium on Red Hat systems, enabling an attacker to gain further access beyond the browser's security boundaries. Exploitation requires user interaction with malicious web content.
Дополнительная информация
Статус:
9 Critical
CVSS3
Связанные уязвимости
Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Use after free in WebGL in Google Chrome on Android prior to 151.0.792 ...
Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
9 Critical
CVSS3