Description: | Summary: Google Chrome is prone to multiple vulnerabilities.
Vulnerability Insight: Multiple flaws exist due to
- Heap buffer overflow in TabStrip.
- Heap buffer overflow in WebAudio.
- Use after free in WebRTC.
- Insufficient data validation in Reader Mode.
- Insufficient data validation in Chrome for iOS.
- Object lifecycle issue in audio.
- Use after free in bookmarks.
- Insufficient policy enforcement in appcache.
- Out of bounds memory access in V8.
- Incorrect security UI in Loader.
- Incorrect security UI in TabStrip and Navigation.
- Insufficient policy enforcement in File System API.
- Side-channel information leakage in Network Internals.
- Inappropriate implementation in Referrer.
- Inappropriate implementation in Site isolation.
- Inappropriate implementation in full screen mode.
- Insufficient policy enforcement in Autofill.
- Inappropriate implementation in Compositing.
- Use after free in Network Internals.
- Use after free in tab search.
- Heap buffer overflow in OpenJPEG.
- Side-channel information leakage in autofill.
- Insufficient policy enforcement in navigations.
- Inappropriate implementation in performance APIs.
- Insufficient policy enforcement in extensions.
- Insufficient policy enforcement in QR scanning.
- Insufficient data validation in URL formatting.
- Use after free in Blink.
- Insufficient policy enforcement in payments.
- Uninitialized Use in PDFium.
Vulnerability Impact: Successful exploitation allows attackers to execute arbitrary code, disclose sensitive information and cause denial of service condition.
Affected Software/OS: Google Chrome version prior to 89.0.4389.72 on Windows
Solution: Upgrade to Google Chrome version 89.0.4389.72 or later. Please see the references for more information.
CVSS Score: 8.3
CVSS Vector: AV:N/AC:M/Au:N/C:P/I:P/A:C
|