The fix for CVE-2021-21148 has added a check in |ValueSerializer::WriteJSArrayBuffer| to make sure non-detachable array buffers cannot be transferred. The check can be bypassed with the help of asm.js and property getters.
ae2637e1d681177334781f4a6b614cf249946bb30e4223a9dc2793a92ea03f86
Gentoo Linux Security Advisory 202104-8 - Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the arbitrary execution of code. Versions less than 90.0.4430.93 are affected.
3c0116aeb3e752ff274eefc0030e2c4cfc941c4cf5a69bc7d93086f56b183f77
Debian Linux Security Advisory 4858-1 - Several vulnerabilities have been discovered in the chromium web browser.
06e041eb0996b6bf6de349afabb9921c5d0e7f815b82714c950fc912a4954e80