Coming Soon...

Q-CERT website is currently under maintenance. We should be back shortly. Thank you for yor patience.

Google Chrome rolls out critical security update-December 2021

Issued: 
Thursday, 16 December, 2021
Last Revision: 
Thursday, 16 December, 2021
Vendor: 
Product: 
Severity Level: 
Summary: 

Google has released Chrome version 96.0.4664.110 for Windows, Mac, and Linux. This security update fixes five vulnerabilities, four of which are rated as high risk and one as critical. One of these vulnerability (CVE-2021-4102) is reportedly being exploited in the wild.

 

CVE-2021-4102 affects Chrome's JavaScript engine, allowing attackers to inject and execute malicious code on the targeted computer. The other four vulnerabilities fixed in this release are- CVE-2021-4098, CVE-2021-4099, CVE-2021-4100, and CVE-2021-4101.

 

CVE/Vulnerability

 

     Description 

CVSS3.0 Score

CVE-2021-4102

 

Use after free in V8

n/a

 

                                                                                   Table 1: Vulnerability details

 

 

CVE/Vulnerability 

                Affected Product(s)

           Platform

CVE-2021-4102

                Chrome web browser 

Windows, Mac, and Linux

 

                                                                                   Table 2: Vulnerable versions

Recommendation: 

Organizers are strongly encouraged to upgrade to the stable channel 96.0.4664.110 as soon as possible.