Junglewise Threat Intelligence

CVE-2021-21166: Google Chromium Race Condition Vulnerability

CVE-2021-21166 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Google Chrome, Microsoft Edge, Google Chromium. Vendors: Opera, Google, Microsoft.

Executive brief

A race condition in the audio component of Google Chromium allows a remote attacker to potentially cause heap corruption via a specially crafted HTML page. This vulnerability has been observed being exploited in the wild and affects multiple Chromium-based browsers.

Affected products

  • Google Chrome prior to 89.0.4389.72
  • Microsoft Edge
  • Opera Opera

Timeline

  • 2021-03-02: patched: Chrome version 89.0.4389.72 released to address the issue.
  • 2021-11-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: disclosed

Related threats