Skip to content
COOEY

EXPOSURES › CVE-2021-21193

CVE-2021-21193

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-21193 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

A use-after-free vulnerability in Google Chromium Blink allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.

This vulnerability was actively exploited in the wild (KEV) and could lead to remote code execution, posing a severe risk to organizations relying on Chromium-based browsers. DIBs must ensure their browsers are patched immediately, as unpatched instances could be leveraged for ransomware or data exfiltration. The failure highlights the critical need for timely patch management of widely deployed software components.

Shame score — The vulnerability was actively exploited in the wild and affected multiple widely used browsers, indicating a significant gap in patch management and exposure to remote attackers.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
Critical vulnerability affecting major browser ecosystem
cooey ↗ severe-fallout -0.80
Critical vulnerability affecting major browser ecosystem
"Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page."
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized