CVE-2021-21224: high-severity vulnerability in Google Chrome
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
A type confusion bug in Chrome's V8 engine allowed attackers to run malicious code inside the browser's sandbox by tricking it with a specially crafted webpage. This could let attackers steal data or compromise your computer.
Type confusion vulnerability in V8 (CWE-843) where incorrect type handling enables arbitrary code execution within the Chrome sandbox. Attack vector is remote via crafted HTML; requires user to visit a malicious webpage. Pre-conditions: victim uses vulnerable Chrome version <90.0.4430.85. Impact includes sandbox escape and arbitrary code execution.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.