

Rewterz Threat Alert – APT29 Targeting Government Organizations with Ceeloader Malware – Active IOCs
December 7, 2021
Rewterz Threat Advisory – ICS: Hitachi Energy XMC20 FOX61x and RTU500 OpenLDAP
December 8, 2021
Rewterz Threat Alert – APT29 Targeting Government Organizations with Ceeloader Malware – Active IOCs
December 7, 2021
Rewterz Threat Advisory – ICS: Hitachi Energy XMC20 FOX61x and RTU500 OpenLDAP
December 8, 2021Severity
High
Analysis Summary
CVE-2021-4068
Google Chrome could allow a remote attacker to bypass security restrictions, caused by insufficient validation of untrusted input in new tab page. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to bypass security restrictions.
CVE-2021-4067
Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error in window manager. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.
CVE-2021-40662
Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by an integer underflow in ANGLE. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.
CVE-2021-4065
Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error in autofill. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.
CVE-2021-4064
Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error in screen capture. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.
CVE-2021-4063
Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error in developer tools. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.
CVE-2021-4062
Google Chrome is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by BFCache. By persuading a victim to visit a specially crafted Web site, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVE-2021-4061
Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a type confusion in V8. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.
CVE-2021-4059
Google Chrome could allow a remote attacker to bypass security restrictions, caused by insufficient data validation in loader. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to bypass security restrictions.
CVE-2021-4058
Google Chrome is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by ANGLE. By persuading a victim to visit a specially crafted Web site, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVE-2021-4057
Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error in file API. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.
CVE-2021-4056
Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a type confusion in loader. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.
CVE-2021-4055
Google Chrome is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by extensions. By persuading a victim to visit a specially crafted Web site, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVE-2021-4078
Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a type confusion in V8. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.
CVE-2021-4054
Google Chrome could allow a remote attacker to bypass security restrictions, caused by incorrect security UI in autofill. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to bypass security restrictions.
CVE-2021-4079
Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds write in WebRTC. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to execute arbitrary code on the system.
CVE-2021-4053
Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error in UI. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.
CVE-2021-4052
Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error in web apps. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a denial of service or to execute arbitrary code on the system.
Impact
- Security Bypass
- Code Execution
- Buffer Overflow
Affected Vendors
Affected Products
- Google Chrome 96
Remediation
Upgrade to the latest version of Chrome, available from the Google Chrome Web site.