ZeroHour

CVE-2021-21166

KEVmass1

Race Condition Heap Corruption in Google Chromium (Chrome, Edge, Opera)

CISA: Google Chromium Race Condition Vulnerability

CVSS 3.1
8.8 high
EPSS
27%p98
Published
()
KEV added
AI analysis

Google Chromium contains a race condition (CWE-362) that can lead to heap corruption (CWE-122) when the browser processes a crafted HTML page, meaning an attacker can trigger the flaw simply by getting a user to visit an attacker-controlled or malicious webpage. Successful exploitation of the heap corruption could crash the browser and potentially allow the attacker to execute code within the affected browser process. Because the vulnerable code is in the Chromium engine itself, all Chromium-based browsers are potentially affected, including Google Chrome, Microsoft Edge, Opera, and other derived browsers, across desktop and mobile fleets. CISA added CVE-2021-21166 to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming the flaw is being exploited in the wild, though ransomware use is unknown and no public proof-of-concept is available. EPSS currently assigns a 26.7% probability of exploitation within 30 days (98th percentile), and CVSS scoring has not yet been published.

What to do: Apply the latest patched releases of all Chromium-based browsers in use (Chrome, Edge, Opera, and any derived browsers) per vendor instructions, as required by CISA's KEV listing. Prioritize managed endpoints and any systems where users browse untrusted or internet-facing websites, verify fleet-wide browser versions after updating, and monitor CISA/vendor advisories for ransomware-associated activity since that linkage is currently unknown.

Affected
Google Chromium
Google Chrome (Chromium-based)
Microsoft Edge (Chromium-based)
Opera (Chromium-based)
Other Chromium-based browser vendors Chromium-derived browsers (e.g., Brave, Vivaldi)
Estimated exposure
massbillions of users and installations (Chromium powers Chrome, Edge, Opera and many other browsers) — Chromium is the engine behind the world's most widely used browsers, with Chrome alone holding a majority share of global browser usage and hundreds of millions to billions of active installations, so essentially every browsing fleet is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlefedoraprojectdebian
Products
chrome, fedora, debian linux
Weakness
CWE-362
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news