Junglewise Threat Intelligence

CVE-2021-21193: Google Chromium Blink Use-After-Free Vulnerability

CVE-2021-21193 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Edge, Opera Software Opera, Google Chrome. Vendors: Microsoft, Opera Software, Google.

Executive brief

A use-after-free vulnerability in the Blink engine of Google Chrome allows a remote attacker to potentially exploit heap corruption via a specially crafted HTML page. This vulnerability has been observed being exploited in the wild.

Affected products

  • Google Chrome prior to 89.0.4389.90
  • Microsoft Edge
  • Opera Software Opera

Timeline

  • 2021-03-12: patched: Stable channel update for desktop released.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats