CVE-2021-21166: high-severity vulnerability in Google Chrome
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
A timing flaw in Chrome's audio processing allows attackers to corrupt memory through a specially crafted webpage. This could let them crash the browser or potentially run malicious code.
A data race condition in the audio subsystem of Chrome versions prior to 89.0.4389.72 enables heap corruption exploitation. An attacker delivers a crafted HTML page that triggers concurrent access to shared memory structures; no user interaction beyond visiting the page is required. Successful exploitation results in memory corruption with potential code execution.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.