Junglewise Threat Intelligence

CVE-2021-21206: Google Chromium Blink Use-After-Free Vulnerability

CVE-2021-21206 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Edge, Google Chrome. Vendors: Opera, Microsoft, Google.

Executive brief

A use-after-free vulnerability in the Blink engine of Google Chromium allows remote attackers to execute arbitrary code or cause heap corruption via a specially crafted HTML page. This vulnerability was exploited in the wild prior to being patched.

Affected products

  • Google Chrome prior to 89.0.4389.128
  • Microsoft Edge
  • Opera Opera

Timeline

  • 2021-04-13: patched: Chrome stable channel update 89.0.4389.128 released
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed

Related threats