CVE-2021-21212Google Chrome vulnerability

6 documents6 sources
Severity
6.5MEDIUMNVD
EPSS
0.9%
top 24.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 26
Latest updateMay 24

Description

Incorrect security UI in Network Config UI in Google Chrome on ChromeOS prior to 90.0.4430.72 allowed a remote attacker to potentially compromise WiFi connection security via a malicious WAP.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

CVEListV5google/chromeunspecified90.0.4430.72
NVDgoogle/chrome< 90.0.4430.72
debiandebian/chromium< chromium 90.0.4430.72-1 (bookworm)
Debianchromium/chromium< 90.0.4430.72-1+3

Also affects: Debian Linux 10.0, Fedora 32, 33, 34

🔴Vulnerability Details

2
GHSA
GHSA-h3gg-p3fw-jf9r: Incorrect security UI in Network Config UI in Google Chrome on ChromeOS prior to 902022-05-24
OSV
CVE-2021-21212: Incorrect security UI in Network Config UI in Google Chrome on ChromeOS prior to 902021-04-26

📋Vendor Advisories

3
Chrome
Stable Channel Update for Desktop: CVE-2021-212122021-04-14
Microsoft
Chromium: CVE-2021-21212 Incorrect security UI in Network Config UI2021-04-13
Debian
CVE-2021-21212: chromium - Incorrect security UI in Network Config UI in Google Chrome on ChromeOS prior to...2021