CVE-2021-4062 describes a heap buffer overflow vulnerability in Google Chrome's BFCache, affecting versions prior to 96.0.4664.93, as well as various Debian and Fedora distributions. This high-severity flaw (CVSS 8.8) could allow a remote attacker, after compromising the renderer process, to achieve heap corruption and potentially execute arbitrary code by enticing a user to visit a specially crafted HTML page. While the vulnerability has garnered some community discussion and media coverage, there is currently no evidence of active exploitation, nor are public exploits available in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 96.0.4664.93CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.