Record summary

CVE-2021-21193 has a selected CVSS score of 8.8 (high); EIP currently links 1 repository PoC. CISA lists CVE-2021-21193 in KEV.

Description

Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Nov 3, 2021 · CISA
VulnCheck KEV
Listed · Mar 9, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListBefore 89.0.4389.90affected
CISAVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubmehrzad1994/CVE-2021-21193Repository PoCby mehrzad1994Stars: 0Not analyzed1 file

7.0 KiB

GitHub

PoC details

References

8