Vulnerability record · CVE-2021-21166 · published 9 March 2021
CVE-2021-21166: Google Chrome audio data race leads to heap corruption
Google · Chrome
Chrome before 89.0.4389.72 contains a data race in the audio component that can corrupt heap memory. A remote attacker can trigger it with a crafted HTML page, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it has seen real-world exploitation.
Description
Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and CISA KEV listing make this a high-priority browser flaw, though it requires user interaction.
What it is
Chrome before 89.0.4389.72 contains a data race in the audio component that can corrupt heap memory. A remote attacker can trigger it with a crafted HTML page, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it has seen real-world exploitation.
Impact
Successful exploitation can corrupt heap memory, which an attacker can leverage for code execution or a browser crash in the context of the Chrome process.
Attack surface
Reached over the network by loading a crafted HTML page in Chrome; no privileges are required, but the victim must open the page (UI:R).
Exploitation
Listed in CISA KEV with a 2021-11-03 addition date, and EPSS shows a 30-day probability of 0.26723 (97.9th percentile), indicating elevated exploitation likelihood. No public exploit code or ransomware use is documented in this record.
What to do
- Update Chrome to 89.0.4389.72 or later, and apply the corresponding Fedora, Debian and Gentoo updates.
- Enforce automatic browser updates and verify version compliance across endpoints.
- Restrict or sandbox browser use for high-risk browsing and block untrusted HTML content where feasible.
- Track CISA KEV remediation deadlines and confirm patching within the required window.
Detection
- Monitor for Chrome renderer crashes or abnormal process terminations that could indicate heap corruption attempts.
- Alert on Chrome versions below 89.0.4389.72 in asset inventories.
- Review proxy and browser logs for delivery of suspicious HTML pages to vulnerable Chrome clients.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-21166 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Google Chromium Race Condition Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-21166 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21166), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.