CVE-2021-21193KEV · OVERDUE

Google Chromium Blink Use-After-Free Vulnerability

High · published March 16, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 8.8. It is confirmed in active exploitation. It sits in the 95.2th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
8.8
EPSS
10%
Percentile
95.2
In the wild
Confirmed
What it is

⚡ A crafty HTML page is all it takes to exploit this alarming use-after-free vulnerability in Google Chrome! 🚨 Think of it like a restaurant where a dish is served but the chef forgets to check if the ingredients were fresh, leading to a potentially disastrous meal. Here, an attacker can serve up a crafted page that tricks Chrome into making dangerously unstable decisions. If an attacker successfully exploits this flaw, they can potentially corrupt the heap, leading to arbitrary code execution. This means they could take control of your browser, steal sensitive data, or even manipulate your browsing sessions in really scary ways! Full access to your machine is a real possibility.

Put simply

Think of it like a restaurant where a dish is served but the chef forgets to check if the ingredients were fresh, leading to a potentially disastrous meal. Here, an attacker can serve up a crafted page that tricks Chrome into making dangerously unstable decisions. This vulnerability in Blink occurs when memory that has already been freed is accessed again, allowing attackers to manipulate the heap and run malicious code through crafted HTML pages. It's a sneaky way to leverage memory mismanagement in Chrome versions before 89.0.4389.90.

What to do

If an attacker successfully exploits this flaw, they can potentially corrupt the heap, leading to arbitrary code execution. This means they could take control of your browser, steal sensitive data, or even manipulate your browsing sessions in really scary ways! Full access to your machine is a real possibility. Update your Google Chrome immediately to version 89.0.4389.90 or later to close this security hole. Make sure to enforce secure browsing practices and educate users about potential risks of opening unknown HTML pages. 🛡️ You've got this! By updating your browser, you're taking a giant leap toward fortifying your defenses! 🔐💪

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.09870 · 95.2th percentile
Published
2021-03-16T14:10Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 16 MAR 14:10Z
    Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
    cvelistv5