CVE-2021-38003highunder attackCWE-755

CVE-2021-38003: high-severity vulnerability in Google Chrome

Published · Updated

85Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 39%
from disclosure to weapon410 days
Published on NVDNov 23
1st PoC+410d
CISA KEVNov 3
exploitation probability
39%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
3 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
Action required by CISAfederal deadline: 2021-11-17

Apply updates per vendor instructions.

In short

A flaw in Chrome's V8 JavaScript engine allows attackers to corrupt memory on your computer by tricking you into visiting a malicious webpage. This can lead to crashes or potentially allow the attacker to run harmful code.

Technical detail

Improper bounds checking in V8's memory handling allows remote code execution through heap corruption. Attack vector is network-based (malicious HTML page), requiring user interaction (page visit). Exploitable pre-condition: victim must open crafted webpage in vulnerable Chrome version. Impact includes arbitrary code execution with user privileges.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Google · Chrome
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.