Rewterz
Rewterz Threat Alert – APT29 Targeting Government Organizations with Ceeloader Malware – Active IOCs
December 7, 2021
Rewterz
Rewterz Threat Advisory – ICS: Hitachi Energy XMC20 FOX61x and RTU500 OpenLDAP
December 8, 2021

Rewterz Threat Advisory – Multiple Google Chrome Vulnerabilities

Severity

High

Analysis Summary

CVE-2021-4068

Google Chrome could allow a remote attacker to bypass security restrictions, caused by insufficient validation of untrusted input in new tab page. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to bypass security restrictions.

CVE-2021-4067

Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error in window manager. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.

CVE-2021-40662

Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by an integer underflow in ANGLE. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.

CVE-2021-4065 

Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error in autofill. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.

CVE-2021-4064

Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error in screen capture. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.

CVE-2021-4063 

Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error in developer tools. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.

CVE-2021-4062 

Google Chrome is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by BFCache. By persuading a victim to visit a specially crafted Web site, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.

CVE-2021-4061 

Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a type confusion in V8. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.

CVE-2021-4059 

Google Chrome could allow a remote attacker to bypass security restrictions, caused by insufficient data validation in loader. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to bypass security restrictions.

CVE-2021-4058 

Google Chrome is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by ANGLE. By persuading a victim to visit a specially crafted Web site, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.

CVE-2021-4057 

Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error in file API. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.

CVE-2021-4056 

Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a type confusion in loader. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.

CVE-2021-4055 

Google Chrome is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by extensions. By persuading a victim to visit a specially crafted Web site, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.

CVE-2021-4078 

Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a type confusion in V8. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.

CVE-2021-4054 

Google Chrome could allow a remote attacker to bypass security restrictions, caused by incorrect security UI in autofill. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to bypass security restrictions.

CVE-2021-4079 

Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds write in WebRTC. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE-2021-4053 

Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error in UI. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.

CVE-2021-4052 

Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error in web apps. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.

Impact

  • Security Bypass
  • Code Execution
  • Buffer Overflow

Affected Vendors

  • Google

Affected Products

  • Google Chrome 96

Remediation

Upgrade to the latest version of Chrome, available from the Google Chrome Web site.

https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop.html