First published: Sun Dec 20 2020(Updated: )
Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Credit: chrome-cve-admin@google.com Anonymous
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <88.0.4324.96 | 88.0.4324.96 |
Google Chrome (Trace Event) | <88.0.4324.96 | |
Microsoft Edge (Chromium-based) | <88.0.705.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-21119 has a high severity rating due to its potential to allow remote code execution through heap corruption.
To mitigate CVE-2021-21119, update Google Chrome or Microsoft Edge Chromium to version 88.0.4324.96 or 88.0.705.50 respectively.
CVE-2021-21119 is caused by a use after free condition in the Media component of Google Chrome.
Users of Google Chrome versions prior to 88.0.4324.96 and Microsoft Edge Chromium versions prior to 88.0.705.50 are affected by CVE-2021-21119.
Yes, CVE-2021-21119 can potentially be exploited remotely by attackers through a crafted HTML page.