Google Chrome SimplifiedLowering bug
Added: 04/09/2021Background
Google Chrome is a web browser application available for multiple platforms.Problem
A bug in the SimplifiedLowering function can potentially lead to a heap overflow which can be exploited to execute arbitrary commands when a user opens a malicious web page.Resolution
Upgrade to Google Chrome 87.0.4280.88 or higher.References
https://chromereleases.googleblog.com/2020/12/stable-channel-update-for-desktop.htmlhttps://bugs.chromium.org/p/chromium/issues/detail?id=1150649
Limitations
Exploit works on Windows 64-bit operating systems and requires a user to load the exploit page in Chrome.Platforms
WindowsBack to exploit index