HIGH
CVE-2021-21148
CVSS
8.8
KEV
Description
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Summary dbcve.org
Heap buffer overflow vulnerability in the V8 JavaScript engine used by Google Chrome. A remote attacker can trigger the overflow via a specially crafted HTML page, potentially leading to heap corruption and possible remote code execution.
Mitigation
Update Google Chrome to version 88.0.4324.150 or later to patch the V8 engine. Organizations should deploy the browser update across all affected endpoints.
Weakness (CWE)
CWE-787
Out-of-bounds Write
EPSS Score
19.97%
Probability of exploitation in next 30 days
97.3th percentile
References
http://packetstormsecurity.com/files/162579/Chrome-Array-Transfer-Bypass.html
Third Party Advisory, VDB Entry
https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_4.html
Release Notes
https://crbug.com/1170176
Permissions Required
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7ACWYJ74Z3YN2XH4QMUEGNBC3VXX464L/
Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AUQSMNV7INLDDSD3RKI5S5EAULX2QC7P/
Release Notes
https://security.gentoo.org/glsa/202104-08
Third Party Advisory
https://www.debian.org/security/2021/dsa-4858
Mailing List, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21148
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.