CVE-2021-21166 is a high-severity data race vulnerability in the audio component of Google Chrome versions prior to 89.0.4389.72, affecting various Chrome distributions across Debian and Fedora. This flaw allows a remote unauthenticated attacker to trigger heap corruption by enticing a user to visit a specially crafted HTML page. With a CVSS score of 8.8, successful exploitation could lead to high impact on confidentiality, integrity, and availability. Notably, this vulnerability has been actively exploited in the wild, as confirmed by its presence in the CISA KEV catalog, and garnered significant community and media attention, despite the absence of publicly available exploit code in common repositories.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 89.0.4389.72CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.