CVE-2021-4098 describes an insufficient data validation vulnerability in Mojo within Google Chrome versions prior to 96.0.4664.110. This flaw could allow a remote attacker, after compromising the renderer process, to achieve a sandbox escape through a specially crafted HTML page. Rated with a CVSS score of 7.4 (High), the vulnerability requires user interaction and has a high impact on integrity. While there is no evidence of active exploitation (not in KEV) and no public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 96.0.4664.110CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.