ZeroHour

CVE-2021-21193

KEVmass

Use-After-Free in Google Chromium Blink Engine Actively Exploited

CISA: Google Chromium Blink Use-After-Free Vulnerability

CVSS 3.1
8.8 high
EPSS
10%p95
Published
()
KEV added
AI analysis

CVE-2021-21193 is a use-after-free (CWE-416) in the Blink rendering engine of Google Chrome, with a CVSS 3.1 score of 8.8 (high). It is triggered when a user loads a crafted HTML page in an affected browser, allowing a remote attacker to corrupt heap memory and potentially execute code in the browser renderer process; the attack requires user interaction but no privileges. Anyone running Google Chrome prior to 89.0.4389.90 is affected, as are users of Fedora and Debian systems running Chromium-based browser packages built from the vulnerable code, per the CISA-supplied vendor and product list. Exploitation is confirmed in the wild: the CVE was added to the CISA KEV on 2021-11-03 with a required action of applying vendor updates, and multiple headlines report zero-day attacks against Chrome that were patched by Google. EPSS estimates a 9.9% probability of exploitation in the next 30 days (95th percentile), and no public proof-of-concept is known.

What to do: Upgrade Google Chrome to 89.0.4389.90 or later immediately; Fedora and Debian users should apply the updated Chromium packages through their distro security repositories, checking their package manager for the patched version. Because the flaw is being exploited in the wild and requires only that a user open a crafted HTML page, prioritize this patch across all endpoints and treat untrusted web links with caution until browsers are updated; CISA KEV requires remediation per vendor instructions by the designated due date.

Affected
google chromeprior to 89.0.4389.90
fedora (chromium packages)
debian linux (chromium packages)
Estimated exposure
masson the order of 1–3 billion users (Chrome's global install base, plus Chromium-based builds on Fedora and Debian) — Chrome is the world's dominant desktop browser with a multi-billion-user install base, and the affected Blink engine also underpins Chromium packages distributed by Fedora and Debian, so exposure is far above the mass threshold.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium Blink
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlefedoraprojectdebian
Products
chrome, fedora, debian linux
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news