HIGH
CVE-2021-30563
CVSS
8.8
KEV
Description
Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Summary dbcve.org
Type confusion vulnerability in Google Chrome's V8 JavaScript engine allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. The vulnerability stems from the engine improperly handling object type assumptions, leading to memory corruption that can be weaponized for code execution.
Mitigation
Update Google Chrome to version 91.0.4472.164 or later. Organizations should deploy browser updates through their patch management systems and verify compliance across endpoints.
Weakness (CWE)
CWE-843
Type Confusion
EPSS Score
8.93%
Probability of exploitation in next 30 days
95.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.