CVE-2021-21186

high
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
8.0

Description

Insufficient policy enforcement in QR scanning in Google Chrome on iOS prior to 89.0.4389.72 allowed an attacker who convinced the user to scan a QR code to bypass navigation restrictions via a crafted QR code.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-21186

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-202103-19

OS impact

OSVersionStatusFixed in
arch archfixed3.7.2218.45-1
debian debianbookwormfixed89.0.4389.82-1
debian debianbullseyefixed89.0.4389.82-1
debian debianforkyfixed89.0.4389.82-1
debian debiansidfixed89.0.4389.82-1
debian debiantrixiefixed89.0.4389.82-1

References

Verify integrity in audit chain (admin only). AS-IS.