Google Chrome SimplifiedLowering bug

Added: 04/09/2021

Background

Google Chrome is a web browser application available for multiple platforms.

Problem

A bug in the SimplifiedLowering function can potentially lead to a heap overflow which can be exploited to execute arbitrary commands when a user opens a malicious web page.

Resolution

Upgrade to Google Chrome 87.0.4280.88 or higher.

References

https://chromereleases.googleblog.com/2020/12/stable-channel-update-for-desktop.html
https://bugs.chromium.org/p/chromium/issues/detail?id=1150649

Limitations

Exploit works on Windows 64-bit operating systems and requires a user to load the exploit page in Chrome.

Platforms

Windows

Back to exploit index