CVE-2021-21183 is an inappropriate implementation vulnerability in Google Chrome's performance APIs, affecting versions prior to 89.0.4389.72, as well as various Debian and Fedora distributions. This medium-severity flaw (CVSS 4.3) allows a remote attacker to leak cross-origin data through a crafted HTML page, requiring user interaction but with low attack complexity. While not listed on the KEV catalog and lacking public exploit code, it garnered significant community discussion and media coverage, including reports of it being an actively exploited zero-day at the time of discovery.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 89.0.4389.72CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.