EXPOSURES › CVE-2021-21206
CVE-2021-21206
HIGH ⌖ ON CISA KEV · EXPLOITEDA use-after-free vulnerability in Google Chromium Blink allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
This use-after-free flaw in the Chromium Blink rendering engine enabled remote code execution through malicious web pages, impacting Google Chrome, Microsoft Edge, and Opera. Defense-industrial-base organizations must ensure their Chromium-based browsers are patched, as this vulnerability was actively exploited in the wild and represents a significant compliance risk under NIST 800-171 for unpatched software.
Shame score — A critical use-after-free vulnerability in a widely deployed rendering engine was actively exploited in the wild, demonstrating severe negligence in patching and vulnerability management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
"Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page."
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been"
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |