CVE-2021-37975highunder attackCWE-416

CVE-2021-37975: high-severity vulnerability in Google Chrome

Published · Updated

83Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 35%
from disclosure to weapon
Published on NVDOct 8
CISA KEV+26d
exploitation probability
35%top 2% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
Action required by CISAfederal deadline: 2021-11-17

Apply updates per vendor instructions.

In short

Google Chrome's V8 JavaScript engine had a use-after-free flaw that allowed attackers to corrupt memory and potentially take control of your computer through a malicious website.

Technical detail

Use-after-free vulnerability in V8 JavaScript engine (CWE-416) enables remote code execution via heap corruption when processing crafted HTML. Attack vector is network-based requiring user interaction (visiting malicious page); impacts versions prior to 94.0.4606.71.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Google · Chrome
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.