HIGH
CVE-2021-30632
CVSS
8.8
KEV
Description
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Summary dbcve.org
Out-of-bounds write vulnerability in the V8 JavaScript engine in Google Chrome versions prior to 93.0.4577.82. A remote attacker can exploit this via a crafted HTML page to perform heap corruption, potentially achieving arbitrary code execution.
Mitigation
Update Google Chrome to version 93.0.4577.82 or later. In enterprise environments, use group policy or software distribution tools to ensure widespread deployment.
Weakness (CWE)
CWE-787
Out-of-bounds Write
EPSS Score
63.19%
Probability of exploitation in next 30 days
99.2th percentile
References
http://packetstormsecurity.com/files/172845/Chrome-JIT-Compiler-Type-Confusion.html
Third Party Advisory, VDB Entry
https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop.html
Release Notes
https://crbug.com/1247763
Permissions Required
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4DDW7HAHTS3SDVXBQUY4SURELO5D4X7R/
Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PM7MOYYHJSWLIFZ4TPJTD7MSA3HSSLV2/
Release Notes
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30632
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.