CVE-2021-21206KEV · OVERDUE

Google Chromium Blink Use-After-Free Vulnerability

High · published April 26, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 8.8. It is confirmed in active exploitation. It sits in the 95.1th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
8.8
EPSS
9%
Percentile
95.1
In the wild
Confirmed
What it is

🚨 A sneaky use-after-free vulnerability in Chrome’s Blink engine could let a crafty attacker exploit heap corruption with just a single HTML page! 🔥 Think of it like a restaurant where a chef mistakenly serves an empty plate instead of the main course — the kitchen is still cooking but can be filled with dangerous leftovers from previous orders, leading to chaos! If exploited, this vulnerability could allow attackers to execute arbitrary code on a victim’s machine, potentially leading to data theft or complete takeover. Imagine someone walking in uninvited and taking over your dinner party, rearranging everything to their liking!

Put simply

Think of it like a restaurant where a chef mistakenly serves an empty plate instead of the main course — the kitchen is still cooking but can be filled with dangerous leftovers from previous orders, leading to chaos! This use-after-free flaw occurs when the Blink engine in Chrome does not properly manage memory, allowing a remote attacker to manipulate heap memory through crafted HTML content, ultimately leading to arbitrary code execution.

What to do

If exploited, this vulnerability could allow attackers to execute arbitrary code on a victim’s machine, potentially leading to data theft or complete takeover. Imagine someone walking in uninvited and taking over your dinner party, rearranging everything to their liking! Update Google Chrome to version 89.0.4389.128 or later immediately to mitigate this threat. Ensure all users in your organization are running the patched version and educate them about the importance of not clicking on suspicious links! You've got this! By following these steps, you can keep your system secure and web browsing safe! 🛡️

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.09477 · 95.1th percentile
Published
2021-04-26T16:00Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 26 APR 16:00Z
    Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
    cvelistv5