
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-21218 is a security vulnerability discovered in PDFium component of Google Chrome prior to version 90.0.4430.72. The vulnerability was reported by Zhou Aiting (@zhouat1) of Qihoo 360 Vulcan Team on January 14, 2021, and was addressed in subsequent Chrome updates (Chrome Release).
The vulnerability is classified as an Uninitialized Use issue in PDFium, which allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file. The vulnerability was assigned a Low severity rating and a bounty of $500 was awarded to the researcher who discovered it (Chrome Release).
When exploited, this vulnerability could allow an attacker to access potentially sensitive information from process memory through specially crafted PDF files (Debian Security).
The vulnerability requires a user to open a specially crafted PDF file in Chrome's built-in PDF viewer. The attack vector is remote, as it can be triggered through malicious PDF files delivered over the web (CVE Mitre).
The vulnerability was fixed in Google Chrome version 90.0.4430.72 and later. Users are advised to update their Chrome browser to the latest version. Various Linux distributions have also released security updates to address this vulnerability, including Debian (90.0.4430.85-1~deb10u1), Fedora, and Gentoo (Debian Security, Gentoo Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."