• Skip to main content
  • Skip to primary sidebar
  • Deals
  • Features
  • Guides
  • Chromebooks
  • Videos
  • Podcast
  • More +
    • Reviews
    • Unboxing
    • Upcoming Devices
    • Chromebook Plus
    • Chrome
    • ChromeOS
    • Chrome OS Flex
  • Search
  • Sign Up
  • Log In
Chrome Unboxed – The Latest Chrome OS News

Chrome Unboxed - The Latest Chrome OS News

A Space for All Things Chrome, Google, and More!

  • Deals
  • Features
  • Guides
  • Chromebooks
  • Videos
  • Podcast
  • More +
    • Reviews
    • Unboxing
    • Upcoming Devices
    • Chromebook Plus
    • Chrome
    • ChromeOS
    • Chrome OS Flex
  • Search
  • Sign Up
  • Log In

Another Zero-Day exploit: Time to update your Chrome browser

June 18, 2021 By Gabriel Brangers View Comments

Support our independent tech coverage. Chrome Unboxed is written by real people, for real people—not search algorithms. Join Chrome Unboxed Plus for just $2 a month to get an ad-free experience, access to our private Discord, and more. Learn more about membership here.
START FREE TRIAL (MONTHLY)START FREE TRIAL (ANNUAL)

Just a week ago, Google rolled out an incremental update to the Chrome Desktop browser that contained a variety of crucial security updates. In that update, the Chrome developer team revealed that one of the vulnerabilities had been actively exploited in the wild. When this happens, it is referred to as a Zero-Day exploit as the software developers were unaware of the weakness prior to the attack. The latest update to the Chrome browser includes only 4 security patches but each of the four is marked “high” which means that they are critical updates. One of the patches does include a fix for a vulnerability that Google has confirmed has been exploited in the wild.

The bug, CVE-2021-30554, was reported by an anonymous source and the bounty for the find is yet to be determined. Google declined to give details on how exactly the bug was exploited. That is likely to give users ample time to get the browser updated to prevent any further attacks. This particular bug is related to WebGL and has been identified as a “user after free” vulnerability. What does that mean? Here’s a brief explanation of what that means.

Xremove ads

Use After Free specifically refers to the attempt to access memory after it has been freed, which can cause a program to crash or, in the case of a Use-After-Free flaw, can potentially result in the execution of arbitrary code or even enable full remote code execution capabilities.

Webopedia

Needless to say, it is probably a good idea to go ahead and make sure your Chrome browser is up to date. The latest version that includes the fix for this bug is 91.0.4472.114. If you are using Chrome on Windows, Linux, or macOS, you will want to head to the about Chrome section in the settings menu and check for an update. If my math is correct, this is the seventh known zero-day exploit for the Chrome browser this year. Thankfully, it appears that it was discovered and patched very quickly. Below you can find the four security patches and their corresponding CVE assignment.

  • [$TBD][1219857] High CVE-2021-30554: Use after free in WebGL. Reported by anonymous on 2021-06-15
  • [$10000][1215029] High CVE-2021-30555: Use after free in Sharing. Reported by David Erceg on 2021-06-01
  • [$7500][1212599] High CVE-2021-30556: Use after free in WebAudio. Reported by Yangkang (@dnpushme) of 360 ATA on 2021-05-24
  • [$10000][1202102] High CVE-2021-30557: Use after free in TabGroups. Reported by David Erceg on 2021-04-23

SUBSCRIBE TO UPSTREAM

Get Chrome Unboxed delivered straight to your inbox

Upstream is our flagship, curated newsletter with the top stories, most click-worthy deals, giveaways, and trending articles from Chrome Unboxed sent directly to your inbox a few times a week. Join 31,000+ subscribers.

Featured Videos

Xremove ads
SUBSCRIBE HERE!

Source: Chrome Release

Filed Under: Apps, Chrome, News

About Gabriel Brangers

Lover of all things coffee. Foodie for life. Passionate drummer, hobby guitar player, Web designer and proud Army Veteran. I have come to drink coffee and tell the world of all things Chrome. "Whatever you do, Carpe the heck out of that Diem" - Roman poet, Horace. Slightly paraphrased.

Primary Sidebar

Xremove ads

Deals

The best Chromebook deals today

By Robby Payne
May 5, 2026

Save $40 on the Google Pixel Watch 4 before the Spring Sale ends

By Joseph Humphrey
April 24, 2026

Deal Alert: the excellent Lenovo Chromebook Plus 2-in-1 returns to $429

By Robby Payne
April 20, 2026

Lenovo Legion Tab Gen 3 drops to $399, ahead of the much pricier Gen 5 release

By Joseph Humphrey
April 18, 2026

How to get 50% off YouTube Premium for a full year with Google One

By Robby Payne
April 16, 2026

More Deals

Xremove ads

Reviews

Lenovo Chromebook Plus 2-in-1 Review: pretty great in a vacuum

By Robby Payne
April 23, 2026

Acer Chromebook Plus Spin 514 Review: Kompanio Ultra power in a convertible

By Robby Payne
December 24, 2025

My review after 6 weeks with the Lenovo Chromebook Plus 14 [VIDEO]

By Robby Payne
August 11, 2025

One week with the best small Android tablet you can buy, and I’m sold

By Robby Payne
May 9, 2025

Best Chromebooks of 2024 [VIDEO]

By Robby Payne
November 28, 2024

More Reviews

Xremove ads

Guides

This Chromebook trackpad shortcut is definitely not new, but is blowing my mind

By Robby Payne
March 11, 2024

How to reduce broadcast delay on YouTube TV to stop live spoilers

By Robby Payne
December 8, 2023

Windows PC keyboard and Chromebook

How to use a Windows keyboard with a Chromebook

By Joseph Humphrey
December 8, 2023

How reset and revert your Chromebook to the previous version of Chrome OS

By Robby Payne
November 29, 2023

My Chromebook Plus features disappeared: here’s how I fixed it

By Robby Payne
November 24, 2023

More Guides

TWITTER · FACEBOOK · INSTAGRAM · YOUTUBE · EMAIL · ABOUT

Copyright © 2026 · Chrome Unboxed · Chrome is a registered trademark of Google Inc.
We are participants in various affiliate advertising programs designed to provide a means for us to earn fees by linking to affiliated sites.

PRIVACY POLICY