CVE-2021-21180 is a high-severity use-after-free vulnerability in Google Chrome's tab search feature, affecting versions prior to 89.0.4389.72, including various Debian and Fedora distributions. This flaw allows a remote attacker to potentially exploit heap corruption by enticing a user to visit a crafted HTML page, leading to high impacts on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, media reports indicate it was actively exploited as a zero-day, though no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability garnered significant community discussion and media coverage, highlighting its importance despite the lack of public exploit intelligence.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 89.0.4389.72CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.