CVE-2021-21191: Use after free in WebRTC
Published Jan 15, 2021
·Updated
Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
raven@@raid_akame
Affected Software
5 affected componentsFixes available
debian/chromium
90.0.4430.212-1~deb10u1116.0.5845.180-1~deb11u1118.0.5993.70-1~deb11u1116.0.5845.180-1~deb12u1118.0.5993.70-1~deb12u1118.0.5993.70-1
Google Chrome<89.0.4389.90
89.0.4389.90
Google Chrome<89.0.4389.90
Fedoraproject Fedora=32
Debian Debian Linux=10.0
Remediation
Patch Available
Event History
Jan 15, 2021
CVE Published
12:00 AM
Mar 16, 2021
CVE Published
via MITRE·02:10 PM
Data Sourced
via MITRE·02:10 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-21191?
CVE-2021-21191 is a vulnerability in WebRTC in Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
2
How can CVE-2021-21191 affect me?
CVE-2021-21191 can potentially allow a remote attacker to exploit heap corruption in Google Chrome.
3
What is the severity of CVE-2021-21191?
The severity of CVE-2021-21191 is not specified in the provided information.
4
How do I fix CVE-2021-21191?
To fix CVE-2021-21191, update to Google Chrome version 89.0.4389.90 or later.
5
Where can I find more information about CVE-2021-21191?
More information about CVE-2021-21191 can be found on the Debian security tracker: https://security-tracker.debian.org/tracker/CVE-2021-21191