LiveActive security incident?Get immediate response
CVE Record

CVE-2021-4320: Use after free in Blink in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromis...

Use after free in Blink in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2021-4320 is a high-severity Google Chrome Blink memory safety flaw. The provided record says a remote attacker who already compromised the renderer process could use a crafted HTML page to gain arbitrary read/write capability. It affects Chrome prior to 92.0.4515.107, according to the description.

Executive priority

Prioritize this as a browser hygiene and legacy exposure issue. It is high severity, but the provided evidence does not show active exploitation. The business action is to confirm no outdated Chrome or Chromium builds remain in production.

Technical view

The vulnerability is a use-after-free in Blink in Google Chrome before 92.0.4515.107. The source states exploitation requires a compromised renderer process and a crafted HTML page, leading to arbitrary read/write. The bundle provides no CVSS vector, CWE, exploit details, or separate mitigation beyond vendor updates.

Likely exposure

Exposure is most likely on endpoints running outdated Chrome or Chromium-derived packages older than the vendor-fixed 92.0.4515.107 line. Managed enterprise browser fleets, legacy images, and unpatched Linux packages are the main places to check.

Exploitation context

The provided sources do not show CISA KEV listing or active exploitation. The stated attacker model requires prior renderer compromise, so this is not described as a one-click standalone compromise in the bundle. Treat it as serious because arbitrary read/write in browser memory can support chained attacks.

Researcher notes

Key gaps are CVSS, CWE mapping, detailed affected range, and public bug details. The crbug reference may be restricted. Analysis should stay anchored to the CVE text, Chrome release note, and Fedora package advisory unless additional vendor data is obtained.

Mitigation direction

  • Update Google Chrome to 92.0.4515.107 or a later supported release.
  • Update Chromium packages using the relevant operating system vendor advisory.
  • Enforce automatic browser updates through endpoint or browser management policy.
  • Check vendor guidance before applying nonstandard mitigations or workarounds.

Validation and detection

  • Inventory Chrome and Chromium versions across managed endpoints.
  • Confirm installed versions are 92.0.4515.107 or later supported builds.
  • Review Linux package status against the Fedora advisory where applicable.
  • Check browser management reports for devices blocked from auto-update.
  • Identify unsupported Chromium forks that may not have received the fix.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-4320 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
GoogleChrome92.0.4515.107Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.