CVE-2021-21160 is a high-severity heap buffer overflow vulnerability in Google Chrome's WebAudio component, affecting versions prior to 89.0.4389.72, as well as various Debian and Fedora distributions. A remote attacker could exploit this flaw by tricking a user into visiting a specially crafted HTML page, potentially leading to arbitrary code execution, data compromise, or denial of service. With a CVSS score of 8.8, it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. This vulnerability was actively exploited as a zero-day at the time of its discovery, garnering substantial media coverage and community discussion, though no public exploit code or Metasploit modules are currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 89.0.4389.72CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.