CVE-2021-21166

CVE Published 2021-03-09
Related CWE(s) CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Related Vendor(s) fedoraproject, debian, google
Related Product(s) fedora, chrome, debian_linux
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 8.8 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References