Vulnerability record · CVE-2021-21206 · published 26 April 2021
CVE-2021-21206: Google Chrome Blink use-after-free enables heap corruption
Google · Chrome
Google Chrome before 89.0.4389.128 contains a use-after-free flaw in the Blink rendering engine. A crafted HTML page can trigger the bug and corrupt the heap, which matters because Chrome is widely deployed and the flaw was exploited in the wild.
Description
Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is remotely reachable via a crafted page, has high CVSS impact, and is listed in CISA KEV as exploited in the wild.
What it is
Google Chrome before 89.0.4389.128 contains a use-after-free flaw in the Blink rendering engine. A crafted HTML page can trigger the bug and corrupt the heap, which matters because Chrome is widely deployed and the flaw was exploited in the wild.
Impact
An attacker can corrupt heap memory in the browser process, which can lead to code execution in the context of the user. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network by a crafted HTML page; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N), so a victim must open or view the page. No authentication is needed.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2021-11-03, indicating active exploitation; EPSS 30-day probability is 0.09307 (95th percentile). No ransomware campaign use is documented.
What to do
- Update Google Chrome to 89.0.4389.128 or later, and apply the corresponding Fedora and Gentoo updates.
- Enable automatic browser updates and verify version compliance across managed endpoints.
- Restrict or sandbox browser use for high-risk browsing and block untrusted HTML content where feasible.
- Track CISA KEV remediation due date (2021-11-17) and confirm patching is complete.
Detection
- Monitor for Chrome renderer crashes or abnormal process terminations that may indicate heap corruption attempts.
- Hunt for known exploitation indicators against Chrome/Blink use-after-free activity in endpoint and network telemetry.
- Check endpoint inventories for Chrome versions below 89.0.4389.128 and flag them for immediate update.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-21206 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Google Chromium Blink Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-21206 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21206), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.