CVE-2021-21192: Heap buffer overflow in tab groups
Published Feb 23, 2021
·Updated
Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Abdulrahman Alqabandi, Microsoft Browser Vulnerability Research
Affected Software
5 affected componentsFixes available
debian/chromium
90.0.4430.212-1~deb10u1116.0.5845.180-1~deb11u1118.0.5993.70-1~deb11u1116.0.5845.180-1~deb12u1118.0.5993.70-1~deb12u1118.0.5993.70-1
Google Chrome<89.0.4389.90
89.0.4389.90
Google Chrome<89.0.4389.90
Fedoraproject Fedora=32
Debian Debian Linux=10.0
Remediation
Patch Available
Event History
Feb 23, 2021
CVE Published
12:00 AM
Mar 16, 2021
CVE Published
via MITRE·02:10 PM
Data Sourced
via MITRE·02:10 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-21192?
CVE-2021-21192 has a high severity rating due to its potential for remote exploitation via crafted HTML pages.
2
How do I fix CVE-2021-21192?
To fix CVE-2021-21192, update your Google Chrome or Chromium browser to the versions 90.0.4430.212 or higher.
3
Which software versions are affected by CVE-2021-21192?
CVE-2021-21192 affects Google Chrome versions prior to 89.0.4389.90 and specific versions of Chromium on Debian and Fedora.
4
Is there a workaround for CVE-2021-21192?
Currently, there are no specific workarounds for CVE-2021-21192; the best prevention is to update your software.
5
What kind of attack is possible with CVE-2021-21192?
CVE-2021-21192 allows for heap buffer overflow attacks that could lead to heap corruption and potential system exploitation.