Wiz Agents & Workflows are here

CVE-2021-30528
vulnerability analysis and mitigation

Overview

CVE-2021-30528 is a Use-after-free vulnerability discovered in the WebAuthentication component of Google Chrome on Android prior to version 91.0.4472.77. The vulnerability was reported by Man Yue Mo of GitHub Security Lab on May 6, 2021, and was fixed in the Chrome release 91.0.4472.77 on May 25, 2021 (GitHub Security Lab, Chrome Release).

Technical details

The vulnerability occurs in the InternalAuthenticatorAndroid::InvokeIsUserVerifyingPlatformAuthenticatorAvailableResponse component. When fetching credit card details for autofill, IsUserVerifyingPlatformAuthenticatorAvailable is called, which then calls the corresponding method of the Java class InternalAuthenticator. The issue arises because mNativeInternalAuthenticatorAndroid is stored in a Java lambda callback, creating a shared reference that can outlive the original object, potentially leading to a use-after-free condition. The vulnerability has been assigned a CVSS v3.1 base score of 8.8 (HIGH) with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (NVD, GitHub Security Lab).

Impact

The vulnerability could allow a remote attacker who has compromised the renderer process of a user who had saved a credit card in their Google account to potentially exploit heap corruption via a crafted HTML page. This could lead to sandbox escape on Android devices (NVD, GitHub Security Lab).

Mitigation and workarounds

The vulnerability was patched in Chrome version 91.0.4472.77. Users and administrators should upgrade to this version or later to mitigate the risk. Various Linux distributions including Fedora and Gentoo have also released security updates to address this vulnerability (Gentoo Advisory, Fedora Update).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management