CVE-2021-37975: high-severity vulnerability in Google Chrome
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
Google Chrome's V8 JavaScript engine had a use-after-free flaw that allowed attackers to corrupt memory and potentially take control of your computer through a malicious website.
Use-after-free vulnerability in V8 JavaScript engine (CWE-416) enables remote code execution via heap corruption when processing crafted HTML. Attack vector is network-based requiring user interaction (visiting malicious page); impacts versions prior to 94.0.4606.71.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.