Skip to content
COOEY

EXPOSURES › CVE-2021-21166

CVE-2021-21166

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-21166 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

A race condition in Google Chromium allows remote attackers to exploit heap corruption via a crafted HTML page, affecting multiple Chromium-based browsers.

This vulnerability enables remote code execution through heap corruption, posing a severe risk to any organization relying on Chromium-based browsers like Chrome or Edge. DIBs must ensure their browsers are patched immediately, as this flaw was actively exploited in the wild and linked to ransomware campaigns. Failure to update exposes systems to arbitrary code execution and potential data breaches.

Shame score — A known race condition in a widely deployed browser was actively exploited in the wild, indicating negligent patching and a failure to protect against common attack vectors.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

SENTIMENT · TRUSTED SOURCES
synthesis negative -0.40
Acknowledged vulnerability, but no strong condemnation.
cooey ↗ negative -0.40
Neutral reporting of facts.
"Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption."
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized