CVE-2021-21166KEV · OVERDUE

Google Chromium Race Condition Vulnerability

High · published March 9, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 8.8. It is confirmed in active exploitation. It sits in the 97.9th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
8.8
EPSS
27%
Percentile
97.9
In the wild
Confirmed
What it is

🚨 A crafty crafted HTML page can exploit a data race in Google Chrome, leading to potential heap corruption! 🔥 Think of it like a crowded subway where two trains are trying to occupy the same platform at the same time, causing chaos and potential derailments. This race condition creates a perfect storm for attackers to hijack control over the system. If an attacker successfully exploits this vulnerability, they could manipulate the heap and potentially take control over your browser, leading to data theft or system crashes. It’s a situation where they could insert malicious code, wreaking havoc on your system from a simple web page. Yikes!

Put simply

Think of it like a crowded subway where two trains are trying to occupy the same platform at the same time, causing chaos and potential derailments. This race condition creates a perfect storm for attackers to hijack control over the system. This vulnerability arises from a data race condition in the audio component of Google Chrome, allowing remote attackers to induce heap corruption via specially crafted HTML pages.

What to do

If an attacker successfully exploits this vulnerability, they could manipulate the heap and potentially take control over your browser, leading to data theft or system crashes. It’s a situation where they could insert malicious code, wreaking havoc on your system from a simple web page. Yikes! Update Google Chrome immediately to version 89.0.4389.72 or later to patch this dangerous flaw. Additionally, consider implementing safe browsing practices to minimize exposure to malicious web content. This is fixable! Stay vigilant and update your browser to lock down your defenses. 🛡️

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.26525 · 97.9th percentile
Published
2021-03-09T17:46Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 09 MAR 17:46Z
    Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
    cvelistv5