CVE-2021-21147: Inappropriate implementation in Skia
Published Jan 4, 2021
·Updated
Inappropriate implementation in Skia in Google Chrome prior to 88.0.4324.146 allowed a local attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Credit
Roman Starkov
Affected Software
4 affected componentsFixes available
Google Chrome<88.0.4324.146
88.0.4324.146
Google Chrome<88.0.4324.146
fedoraproject fedora=32
fedoraproject fedora=33
Event History
Jan 4, 2021
CVE Published
12:00 AM
Feb 9, 2021
CVE Published
via MITRE·02:55 PM
Data Sourced
via MITRE·02:55 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2021-21147?
CVE-2021-21147 is rated as a high severity vulnerability due to the potential for spoofing the Omnibox contents.
2
How do I fix CVE-2021-21147?
To fix CVE-2021-21147, users should update Google Chrome to version 88.0.4324.146 or later.
3
Who is affected by CVE-2021-21147?
CVE-2021-21147 affects users of Google Chrome prior to version 88.0.4324.146 and Fedora versions 32 and 33.
4
What types of attacks can exploit CVE-2021-21147?
CVE-2021-21147 can be exploited by local attackers to spoof the URL bar using a specially crafted HTML page.
5
When was CVE-2021-21147 disclosed?
CVE-2021-21147 was disclosed on February 2, 2021, as part of a Chrome update.