HIGH
CVE-2021-21166
CVSS
8.8
KEV
Description
Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Summary dbcve.org
A data race vulnerability in Google Chrome's audio component (versions prior to 89.0.4389.72) allows a remote attacker to exploit heap corruption through a specially crafted HTML page. The race condition occurs in audio processing code, where concurrent access without proper synchronization can lead to memory corruption.
Mitigation
Update Google Chrome to version 89.0.4389.72 or later to patch the data race vulnerability in the audio component.
Weakness (CWE)
CWE-362
Race Condition
EPSS Score
24.03%
Probability of exploitation in next 30 days
97.8th percentile
References
https://chromereleases.googleblog.com/2021/03/stable-channel-update-for-desktop.html
Release Notes
https://crbug.com/1177465
Permissions Required
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BBT54RKAE5XLMWSHLVUKJ7T2XHHYMXLH/
Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FE5SIKEVYTMDCC5OSXGOM2KRPYLHYMQX/
Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LCIDZ77XUDMB2EBPPWCQXPEIJERDNSNT/
Release Notes
https://security.gentoo.org/glsa/202104-08
Third Party Advisory
https://www.debian.org/security/2021/dsa-4886
Mailing List, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21166
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.