CVE-2021-30632: high-severity vulnerability in Google Chrome
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
A flaw in Google Chrome's V8 engine allows attackers to write data outside designated memory boundaries through a malicious webpage, potentially corrupting the heap and taking control of the browser.
An out-of-bounds write vulnerability in V8 allows a remote attacker to write beyond allocated heap memory via a crafted HTML page, potentially enabling arbitrary code execution or heap corruption. Requires user interaction (visiting a malicious site) and affects Chrome versions prior to 93.0.4577.82.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.