CVE-2021-21224
Description
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Summary dbcve.org
A type confusion vulnerability exists in the V8 JavaScript engine in Google Chrome versions prior to 90.0.4430.85. This flaw allows a remote attacker to execute arbitrary code via a specially crafted HTML page by manipulating how the V8 engine handles object types, leading to memory corruption. While the code execution occurs within Chrome's sandbox, the high CVSS score (8.8) reflects the significant impact of remote code execution even in a sandboxed context.
Mitigation
Update Google Chrome to version 90.0.4430.85 or later to patch the V8 type confusion vulnerability. For enterprise environments, deploy the update via centralized software distribution or group policy and verify completion across all managed endpoints.