HIGH

CVE-2021-21148

Google Chrome 2021-02-09 CVSS v3.1
CVSS
8.8
KEV

Description

Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Summary dbcve.org

Heap buffer overflow vulnerability in the V8 JavaScript engine used by Google Chrome. A remote attacker can trigger the overflow via a specially crafted HTML page, potentially leading to heap corruption and possible remote code execution.

Mitigation

Update Google Chrome to version 88.0.4324.150 or later to patch the V8 engine. Organizations should deploy the browser update across all affected endpoints.

Proof of Concept

Weakness (CWE)

CWE-787 Out-of-bounds Write

EPSS Score

19.97%
Probability of exploitation in next 30 days
97.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE