CVE-2021-21135 is a medium-severity vulnerability affecting Google Chrome and Microsoft Edge (Chromium-based) versions prior to 88.0.4324.96. It stems from an inappropriate implementation in the Performance API, allowing a remote attacker to leak cross-origin data through a specially crafted HTML page. The vulnerability has a CVSS score of 6.5, indicating a high potential for confidentiality impact with low attack complexity, requiring user interaction. While there is no evidence of active exploitation, public exploit code, or KEV listing, it has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 88.0.4324.96CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 88.0.705.50CPE matchmatch criteria | cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.