EXPOSURES › CVE-2021-21166
CVE-2021-21166
HIGH ⌖ ON CISA KEV · EXPLOITEDA race condition in Google Chromium allows remote attackers to exploit heap corruption via a crafted HTML page, affecting multiple Chromium-based browsers.
This vulnerability enables remote code execution through heap corruption, posing a severe risk to any organization relying on Chromium-based browsers like Chrome or Edge. DIBs must ensure their browsers are patched immediately, as this flaw was actively exploited in the wild and linked to ransomware campaigns. Failure to update exposes systems to arbitrary code execution and potential data breaches.
Shame score — A known race condition in a widely deployed browser was actively exploited in the wild, indicating negligent patching and a failure to protect against common attack vectors.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
"Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption."
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |