LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-30633: Google Chromium Indexed DB API Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-30633 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted…

CVE-2021-30633 is a use-after-free vulnerability in the Google Chromium Indexed DB API. A remote attacker who has already compromised the renderer process can potentially escape the browser sandbox by means of a crafted HTML page. Because many browsers are built on Chromium, the issue can affect Google Chrome, Microsoft Edge, Opera, and other Chromium-based products. Teams should treat it as a high-priority browser risk and confirm exact impact and fixes against the vendor advisory.

How it works

The weakness is classified as CWE-416 (use-after-free). In this class of flaw, memory is freed while a pointer to it remains in use; subsequent access can corrupt memory or allow unintended code paths. Per the CISA summary, an attacker who has already compromised the renderer process can abuse the Indexed DB API path with a crafted HTML page to attempt a sandbox escape. Public detail does not describe the precise memory objects or trigger sequence; defenders should treat any successful renderer compromise combined with malicious web content as a potential path to broader browser process control and should verify technical specifics only in the vendor advisory.

Am I affected? How to find it in your systems

Chromium-based browsers are common on endpoints, VDI images, kiosks, and developer workstations. Inventory every browser that embeds Chromium—Google Chrome, Microsoft Edge, Opera, and any other Chromium derivative—across managed and unmanaged devices.

If version or configuration data is unclear, assume potential exposure until you confirm against the vendor advisory.

How to remediate

Patch first. Apply the updates issued by each browser vendor exactly as directed in their advisories; CISA’s required action is to apply updates per vendor instructions. After patching:

If you can't patch immediately

Reduce exposure until updates can be deployed:

If your data may have been exposed

Actively exploited browser sandbox-escape vulnerabilities can lead to further compromise of the endpoint and potential data exposure. Known ransomware use of this CVE is not documented in the provided facts. If you suspect exploitation, follow your incident-response process: isolate affected hosts, preserve evidence, rotate credentials that may have been accessible from the browser session, and assess lateral movement. You can run a free exposure scan of your email addresses against known breach data to check whether associated credentials or personal data have appeared in prior breaches while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGoogle · Chromium Indexed DB API
WeaknessCWE-416
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities