First published: Fri Nov 20 2020(Updated: )
Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit: chrome-cve-admin@google.com YoungJoo Lee @ashuu_lee Raon Whitehat
Affected Software | Affected Version | How to fix |
---|---|---|
debian/chromium | 90.0.4430.212-1~deb10u1 116.0.5845.180-1~deb11u1 118.0.5993.70-1~deb11u1 116.0.5845.180-1~deb12u1 118.0.5993.70-1~deb12u1 118.0.5993.70-1 | |
Google Chrome (Trace Event) | <87.0.4280.141 | 87.0.4280.141 |
Google Chrome (Trace Event) | <87.0.4280.141 | |
Fedora | =32 | |
Fedora | =33 | |
Debian | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-21112 has a high severity due to its potential to allow a remote attacker to exploit heap corruption.
To fix CVE-2021-21112, update Google Chrome to version 87.0.4280.141 or later.
CVE-2021-21112 affects versions of Google Chrome prior to 87.0.4280.141.
Yes, CVE-2021-21112 can potentially be exploited through crafted HTML pages, including those embedded in email attachments.
It is recommended to keep all web browsers up to date and to avoid opening untrusted links or files.