CVE-2021-21141 describes an insufficient policy enforcement vulnerability in the File System API of Google Chrome and Microsoft Edge prior to specific versions. This flaw allowed a remote attacker to bypass file extension policies through a specially crafted HTML page. With a CVSS score of 6.5 (Medium), it requires user interaction (UI:R) but can lead to high integrity impact (I:H) if exploited. While no active exploitation, public exploit code, or KEV listing is reported, it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 88.0.4324.96CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 88.0.705.74CPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.