CVE-2021-21220highunder attackCWE-787

CVE-2021-21220: high-severity vulnerability in Google Chrome

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 8.8epss 70%
from disclosure to weapon153 days
Published on NVDApr 26
1st PoC+153d
metasploitApr 13
CISA KEV+191d
exploitation probability
70%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
7 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
Action required by CISAfederal deadline: 2021-11-17

Apply updates per vendor instructions.

In short

Google Chrome's V8 engine did not properly validate untrusted input, allowing attackers to corrupt memory on a victim's computer through a specially crafted webpage. This could lead to crashes or potentially malicious code execution.

Technical detail

CWE-787 (out-of-bounds write) in V8 engine due to insufficient input validation. Remote attack vector via crafted HTML; no user interaction beyond visiting a malicious page required. Successful exploitation results in heap corruption, enabling potential code execution with renderer process privileges.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Google · Chrome
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.