CVE-2021-21220: high-severity vulnerability in Google Chrome
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
Google Chrome's V8 engine did not properly validate untrusted input, allowing attackers to corrupt memory on a victim's computer through a specially crafted webpage. This could lead to crashes or potentially malicious code execution.
CWE-787 (out-of-bounds write) in V8 engine due to insufficient input validation. Remote attack vector via crafted HTML; no user interaction beyond visiting a malicious page required. Successful exploitation results in heap corruption, enabling potential code execution with renderer process privileges.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.