CVE-2021-21166highunder attackCWE-362

CVE-2021-21166: high-severity vulnerability in Google Chrome

Published · Updated

56Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Actcvss 8.8epss 24%
from disclosure to weapon
Published on NVDMar 9
CISA KEV+239d
exploitation probability
24%top 2% of all CVEs
observed exploitation
yesCISA + VulnCheck
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
Action required by CISAfederal deadline: 2021-11-17

Apply updates per vendor instructions.

In short

A timing flaw in Chrome's audio processing allows attackers to corrupt memory through a specially crafted webpage. This could let them crash the browser or potentially run malicious code.

Technical detail

A data race condition in the audio subsystem of Chrome versions prior to 89.0.4389.72 enables heap corruption exploitation. An attacker delivers a crafted HTML page that triggers concurrent access to shared memory structures; no user interaction beyond visiting the page is required. Successful exploitation results in memory corruption with potential code execution.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Google · Chrome