ZeroHour

CVE-2021-21206

KEVmass

Use-After-Free in Google Chrome Blink Engine Exploited in the Wild

CISA: Google Chromium Blink Use-After-Free Vulnerability

CVSS 3.1
8.8 high
EPSS
9%p95
Published
()
KEV added
AI analysis

Google Chrome and Chromium versions prior to 89.0.4389.128 contain a use-after-free flaw (CWE-416) in the Blink rendering engine. A remote attacker can trigger it by luring a user into opening a crafted HTML page, requiring no privileges and only user interaction, which corrupts browser process memory (heap corruption) and can potentially allow arbitrary code execution within the browser. All users of Chrome or Chromium builds older than 89.0.4389.128 are affected, including the Chromium package shipped by Fedora. Google fixed the bug as an actively exploited zero-day in the same release as CVE-2021-21205, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03; EPSS estimates a 9.3% probability of exploitation within 30 days (95th percentile).

What to do: Upgrade Google Chrome/Chromium to 89.0.4389.128 or later (verify via chrome://settings/help) and apply Fedora's updated chromium package, then restart the browser so the fix takes effect. Because the flaw is listed in CISA's KEV catalog and was exploited in the wild, prioritize patching for internet-exposed and high-risk users; no public PoC is known, but treat in-the-wild exploitation as confirmed.

Affected
Google Chromeprior to 89.0.4389.128 (Windows, macOS, Linux)
Google Chromium (Blink engine)prior to 89.0.4389.128
Fedora Project chromium (Fedora package)Chromium builds prior to 89.0.4389.128; fixed via Fedora security updates
Estimated exposure
massbillions of users (Chrome's global install base exceeds 3 billion; ~65% desktop browser market share) — Chrome's worldwide install base and dominant browser market share mean the exposed population is effectively every Chrome/Chromium user on a build older than 89.0.4389.128; the exact count of unpatched installs at the time is unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium Blink
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlefedoraproject
Products
chrome, fedora
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news