CVE-2021-21112
published 2021-01-08CVE-2021-21112: Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
PriorityP344high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.35%
68.7th percentile
Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 87.0.4280.141-0.1 | 87.0.4280.141-0.1 |
| chromium | chromium | >= 0 < 87.0.4280.141-0.1 | 87.0.4280.141-0.1 |
| chromium | chromium | >= 0 < 87.0.4280.141-0.1 | 87.0.4280.141-0.1 |
| chromium | chromium | >= 0 < 87.0.4280.141-0.1 | 87.0.4280.141-0.1 |
| debian | chromium | < chromium 87.0.4280.141-0.1 (bookworm) | chromium 87.0.4280.141-0.1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 87.0.4280.141 | 87.0.4280.141 | |
| chrome | >= unspecified < 87.0.4280.141 | 87.0.4280.141 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gx2v-252m-68c8: Use after free in Blink in Google Chrome prior to 87
ghsa_unreviewed·2022-05-24
CVE-2021-21112 [HIGH] CWE-416 GHSA-gx2v-252m-68c8: Use after free in Blink in Google Chrome prior to 87
Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
OSV
CVE-2021-21112: Use after free in Blink in Google Chrome prior to 87
osv·2021-01-08·CVSS 8.8
CVE-2021-21112 [HIGH] CVE-2021-21112: Use after free in Blink in Google Chrome prior to 87
Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Citrix
CVE-2021-34424: A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Mee
vendor_citrix·2021-11-24·CVSS 7.5
CVE-2021-34424 [HIGH] CWE-125 CVE-2021-34424: A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Mee
CVE-2021-34424: A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings for Chrome OS before version 5.0.1, Zoom Rooms for Conference Room (for Android, AndroidBali, macOS, and Windows) before version 5.8.3, Controllers for Zoom Rooms (for Android, iOS, and Windows) before version 5.8.3, Zoom VDI Windows Meeting Client before version 5.8.4, Zoom VDI Azure Virtual Desktop Plugins (for Windows x86 or x64, IGEL x64, Ubuntu x64, HP ThinPro OS x64) before version 5.8.4.21112, Zoom VDI Citrix Plugins (for Windows x86 or x64, Mac Univers
Chrome
Stable Channel Update for Desktop: CVE-2021-21112
vendor_chrome·2021-01-06·CVSS 8.8
CVE-2021-21112 [HIGH] Stable Channel Update for Desktop: CVE-2021-21112
Stable Channel Update for Desktop
CVE-2021-21112: Use after free in Blink. Reported by YoungJoo Lee(@ashuu_lee) of Raon Whitehat on 2020-11-20 [$6000][ 1155178 ] High CVE-2021-21113: Heap buffer overflow in Skia
Reported by tsubmunu on 2020-12-03 [$N/A][ 1148309 ] High CVE-2020-16043: Insufficient data validation in networking
Severity: high
Debian
CVE-2021-21112: chromium - Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote...
vendor_debian·2021·CVSS 8.8
CVE-2021-21112 [HIGH] CVE-2021-21112: chromium - Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote...
Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.141-0.1)
bullseye: resolved (fixed in 87.0.4280.141-0.1)
forky: resolved (fixed in 87.0.4280.141-0.1)
sid: resolved (fixed in 87.0.4280.141-0.1)
trixie: resolved (fixed in 87.0.4280.141-0.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop.htmlhttps://crbug.com/1151298https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VVUWIJKZTZTG6G475OR6PP4WPQBVM6PS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z6P6AVVFP7B2M4H7TJQBASRZIBLOTUFN/https://security.gentoo.org/glsa/202101-05https://www.debian.org/security/2021/dsa-4832https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop.htmlhttps://crbug.com/1151298https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VVUWIJKZTZTG6G475OR6PP4WPQBVM6PS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z6P6AVVFP7B2M4H7TJQBASRZIBLOTUFN/https://security.gentoo.org/glsa/202101-05https://www.debian.org/security/2021/dsa-4832
2021-01-08
Published