CVE-2021-30632highunder attackCWE-787

CVE-2021-30632: high-severity vulnerability in Google Chrome

Published · Updated

83Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 63%
from disclosure to weapon0 days
Published on NVDOct 8
1st PoCSep 20
CISA KEV+26d
exploitation probability
63%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
7 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
Action required by CISAfederal deadline: 2021-11-17

Apply updates per vendor instructions.

In short

A flaw in Google Chrome's V8 engine allows attackers to write data outside designated memory boundaries through a malicious webpage, potentially corrupting the heap and taking control of the browser.

Technical detail

An out-of-bounds write vulnerability in V8 allows a remote attacker to write beyond allocated heap memory via a crafted HTML page, potentially enabling arbitrary code execution or heap corruption. Requires user interaction (visiting a malicious site) and affects Chrome versions prior to 93.0.4577.82.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Google · Chrome
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.