CVE-2021-21163 is a medium-severity vulnerability affecting Google Chrome on iOS, specifically versions prior to 89.0.4389.72, as well as related products from Apple, Debian, and Fedora. This flaw, categorized as insufficient data validation (CWE-346), allowed a remote attacker to leak cross-origin data through a crafted HTML page and a malicious server. With a CVSS score of 6.5, it requires user interaction (UI:R) and has high confidentiality impact (C:H) but no integrity or availability impact. Although no public exploit code (Metasploit, Nuclei, ExploitDB) is available, this vulnerability was actively exploited as a zero-day and received significant community and media attention, including mentions on Reddit and coverage by BleepingComputer and SecurityWeek.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 89.0.4389.72CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.