Vulnerability record · CVE-2021-30554 · published 2 July 2021
CVE-2021-30554: Google Chrome WebGL use-after-free enables heap corruption
Google · Chrome
Google Chrome before 91.0.4472.114 contains a use-after-free flaw in WebGL. A crafted HTML page can trigger the bug and corrupt heap memory, which makes it a serious browser-side memory safety issue.
Description
Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote, unauthenticated code execution risk in a widely deployed browser with confirmed exploitation per CISA KEV, though it requires user interaction.
What it is
Google Chrome before 91.0.4472.114 contains a use-after-free flaw in WebGL. A crafted HTML page can trigger the bug and corrupt heap memory, which makes it a serious browser-side memory safety issue.
Impact
An attacker who gets the page rendered can potentially achieve heap corruption, which typically leads to code execution or a crash in the browser process. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network by loading a crafted HTML page in Chrome; the vector requires user interaction (UI:R) and no privileges (PR:N). No authentication is needed.
Exploitation
Listed in CISA KEV with a 2021-11-03 addition and 2021-11-17 remediation due date, indicating known exploitation. EPSS 30-day probability is 0.07367 (94th percentile), and no ransomware campaign use is documented.
What to do
- Update Chrome to 91.0.4472.114 or later, and apply the corresponding Fedora and Gentoo package updates.
- Enforce automatic browser updates and verify version compliance across endpoints.
- Restrict or disable WebGL where it is not required by business applications.
- Keep browser and OS patching on a short cycle given the KEV listing.
Detection
- Alert on Chrome versions below 91.0.4472.114 in asset inventory.
- Monitor for browser crashes or renderer process terminations that could indicate heap corruption attempts.
- Hunt for exploit delivery via crafted HTML pages and suspicious WebGL-related content in web or email gateways.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-30554 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Google Chromium WebGL Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-30554 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-30554), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.