CVE-2021-21224highunder attackCWE-843

CVE-2021-21224: high-severity vulnerability in Google Chrome

Published · Updated

93Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 84%
from disclosure to weapon681 days
Published on NVDApr 26
1st PoC+681d
CISA KEV+191d
exploitation probability
84%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
Action required by CISAfederal deadline: 2021-11-17

Apply updates per vendor instructions.

In short

A type confusion bug in Chrome's V8 engine allowed attackers to run malicious code inside the browser's sandbox by tricking it with a specially crafted webpage. This could let attackers steal data or compromise your computer.

Technical detail

Type confusion vulnerability in V8 (CWE-843) where incorrect type handling enables arbitrary code execution within the Chrome sandbox. Attack vector is remote via crafted HTML; requires user to visit a malicious webpage. Pre-conditions: victim uses vulnerable Chrome version <90.0.4430.85. Impact includes sandbox escape and arbitrary code execution.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Google · Chrome
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.