HIGH

CVE-2021-21224

Google Chrome 2021-04-26 CVSS v3.1
CVSS
8.8
KEV

Description

Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

Summary dbcve.org

A type confusion vulnerability exists in the V8 JavaScript engine in Google Chrome versions prior to 90.0.4430.85. This flaw allows a remote attacker to execute arbitrary code via a specially crafted HTML page by manipulating how the V8 engine handles object types, leading to memory corruption. While the code execution occurs within Chrome's sandbox, the high CVSS score (8.8) reflects the significant impact of remote code execution even in a sandboxed context.

Mitigation

Update Google Chrome to version 90.0.4430.85 or later to patch the V8 type confusion vulnerability. For enterprise environments, deploy the update via centralized software distribution or group policy and verify completion across all managed endpoints.

Proof of Concept

Weakness (CWE)

CWE-843 Type Confusion

EPSS Score

84.17%
Probability of exploitation in next 30 days
99.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE