CVE-2021-21107
published 2021-01-08CVE-2021-21107: Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to…
PriorityP346critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
EPSS
1.12%
62.4th percentile
Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 87.0.4280.141-0.1 | 87.0.4280.141-0.1 |
| chromium | chromium | >= 0 < 87.0.4280.141-0.1 | 87.0.4280.141-0.1 |
| chromium | chromium | >= 0 < 87.0.4280.141-0.1 | 87.0.4280.141-0.1 |
| chromium | chromium | >= 0 < 87.0.4280.141-0.1 | 87.0.4280.141-0.1 |
| debian | chromium | < chromium 87.0.4280.141-0.1 (bookworm) | chromium 87.0.4280.141-0.1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 87.0.4280.141 | 87.0.4280.141 | |
| chrome | >= unspecified < 87.0.4280.141 | 87.0.4280.141 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.6CRITICAL
vendor_debian9.6CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4456-4h4r-g935: Use after free in drag and drop in Google Chrome on Linux prior to 87
ghsa_unreviewed·2022-05-24
CVE-2021-21107 [CRITICAL] CWE-416 GHSA-4456-4h4r-g935: Use after free in drag and drop in Google Chrome on Linux prior to 87
Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
OSV
CVE-2021-21107: Use after free in drag and drop in Google Chrome on Linux prior to 87
osv·2021-01-08·CVSS 9.6
CVE-2021-21107 [CRITICAL] CVE-2021-21107: Use after free in drag and drop in Google Chrome on Linux prior to 87
Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Chrome
Stable Channel Update for Desktop: CVE-2021-21106
vendor_chrome·2021-01-06·CVSS 9.6
CVE-2021-21106 [HIGH] Stable Channel Update for Desktop: CVE-2021-21106
Stable Channel Update for Desktop
CVE-2021-21106: Use after free in autofill. Reported by Weipeng Jiang (@Krace) from Codesafe Team of Legendsec at Qi'anxin Group on 2020-11-13 [$20000][ 1153595 ] High CVE-2021-21107: Use after free in drag and drop
Reported by Leecraso and Guang Gong of 360 Alpha Lab on 2020-11-30 [$20000][ 1155426 ] High CVE-2021-21108: Use after free in media
Severity: high
Debian
CVE-2021-21107: chromium - Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141...
vendor_debian·2021·CVSS 9.6
CVE-2021-21107 [CRITICAL] CVE-2021-21107: chromium - Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141...
Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.141-0.1)
bullseye: resolved (fixed in 87.0.4280.141-0.1)
forky: resolved (fixed in 87.0.4280.141-0.1)
sid: resolved (fixed in 87.0.4280.141-0.1)
trixie: resolved (fixed in 87.0.4280.141-0.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop.htmlhttps://crbug.com/1153595https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VVUWIJKZTZTG6G475OR6PP4WPQBVM6PS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z6P6AVVFP7B2M4H7TJQBASRZIBLOTUFN/https://security.gentoo.org/glsa/202101-05https://www.debian.org/security/2021/dsa-4832https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop.htmlhttps://crbug.com/1153595https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VVUWIJKZTZTG6G475OR6PP4WPQBVM6PS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z6P6AVVFP7B2M4H7TJQBASRZIBLOTUFN/https://security.gentoo.org/glsa/202101-05https://www.debian.org/security/2021/dsa-4832
2021-01-08
Published