Use after free in WebSerial in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-17482
https://chromereleases.googleblog.com/2021/07/stable-channel-update-for-desktop.html