HIGH

CVE-2021-38003

Google Chrome 2021-11-23 CVSS v3.1
CVSS
8.8
KEV

Description

Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Summary dbcve.org

An inappropriate implementation in Google Chrome's V8 JavaScript engine prior to version 95.0.4638.69 allows heap corruption. A remote attacker can exploit this by tricking a user into visiting a crafted HTML page, potentially leading to arbitrary code execution.

Mitigation

Update Google Chrome to version 95.0.4638.69 or later. In enterprise environments, deploy the update via standard software distribution mechanisms (e.g., group policy, SCCM, endpoint management tools).

Proof of Concept

Weakness (CWE)

CWE-755

EPSS Score

38.57%
Probability of exploitation in next 30 days
98.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE