Skip to content
COOEY

EXPOSURES › CVE-2021-21206

CVE-2021-21206

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-21206 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

A use-after-free vulnerability in Google Chromium Blink allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.

This use-after-free flaw in the Chromium Blink rendering engine enabled remote code execution through malicious web pages, impacting Google Chrome, Microsoft Edge, and Opera. Defense-industrial-base organizations must ensure their Chromium-based browsers are patched, as this vulnerability was actively exploited in the wild and represents a significant compliance risk under NIST 800-171 for unpatched software.

Shame score — A critical use-after-free vulnerability in a widely deployed rendering engine was actively exploited in the wild, demonstrating severe negligence in patching and vulnerability management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Widespread acknowledgement of the vulnerability and its potential impact, with no positive commentary.
cooey ↗ severe-fallout -0.70
Neutral reporting of the vulnerability.
"Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page."
app.opencve.io ↗ severe-fallout +0.00
Listing the CVE alongside others, no commentary.
chromereleases.googleblog.com ↗ severe-fallout +0.00
Focus on release updates, no mention of the vulnerability.
cvedb.shodan.io ↗ severe-fallout +0.00
Listing the CVE alongside others, no commentary.
www.cvefind.com ↗ severe-fallout +0.00
Listing the CVE alongside others, no commentary.
www.hipaajournal.com ↗ severe-fallout +0.00
Irrelevant to the security failure.
cvefeed.io ↗ severe-fallout +0.00
Listing the CVE alongside others, no commentary.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been"
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized