CVE-2021-38003: high-severity vulnerability in Google Chrome
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
A flaw in Chrome's V8 JavaScript engine allows attackers to corrupt memory on your computer by tricking you into visiting a malicious webpage. This can lead to crashes or potentially allow the attacker to run harmful code.
Improper bounds checking in V8's memory handling allows remote code execution through heap corruption. Attack vector is network-based (malicious HTML page), requiring user interaction (page visit). Exploitable pre-condition: victim must open crafted webpage in vulnerable Chrome version. Impact includes arbitrary code execution with user privileges.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.