CVE-2021-21206: Google Chromium Blink Use-After-Free Vulnerability
Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Other sources
Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 89.0.4389.128
Event History
Frequently Asked Questions
What is CVE-2021-21206?
CVE-2021-21206 is a use-after-free vulnerability in Google Chromium Blink that can lead to heap corruption.
How can a remote attacker exploit CVE-2021-21206?
A remote attacker can potentially exploit CVE-2021-21206 by using a crafted HTML page.
Which web browsers are affected by CVE-2021-21206?
Web browsers that utilize Chromium, including Google Chrome and Microsoft Edge, are affected by CVE-2021-21206.
What is the severity of CVE-2021-21206?
CVE-2021-21206 has a severity rating of 8.8 (high).
How can I fix CVE-2021-21206?
To fix CVE-2021-21206, users should update to the latest version of Chromium or the affected web browser.