CVE-2021-4099 is a high-severity use-after-free vulnerability in Swiftshader, affecting Google Chrome prior to version 96.0.4664.110. This flaw allowed a remote attacker to achieve heap corruption by enticing a user to visit a specially crafted HTML page. With a CVSS score of 8.8, it presents a significant risk of high impact to confidentiality, integrity, and availability. While not listed on CISA's KEV catalog and lacking public exploit code, the vulnerability garnered notable community discussion and media coverage, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 96.0.4664.110CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.