HIGH
CVE-2021-38003
CVSS
8.8
KEV
Description
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Summary dbcve.org
An inappropriate implementation in Google Chrome's V8 JavaScript engine prior to version 95.0.4638.69 allows heap corruption. A remote attacker can exploit this by tricking a user into visiting a crafted HTML page, potentially leading to arbitrary code execution.
Mitigation
Update Google Chrome to version 95.0.4638.69 or later. In enterprise environments, deploy the update via standard software distribution mechanisms (e.g., group policy, SCCM, endpoint management tools).
Weakness (CWE)
CWE-755
EPSS Score
38.57%
Probability of exploitation in next 30 days
98.5th percentile
References
https://chromereleases.googleblog.com/2021/10/stable-channel-update-for-desktop_28.html
Release Notes
https://crbug.com/1263462
Exploit, Issue Tracking
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3W46HRT2UVHWSLZB6JZHQF6JNQWKV744/
Release Notes
https://www.debian.org/security/2022/dsa-5046
Mailing List, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38003
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.