Executive brief
A type confusion vulnerability in the Google Chromium V8 engine allows a remote attacker to potentially execute arbitrary code or cause heap corruption via a crafted HTML page. The flaw was exploited in the wild prior to being patched and affects multiple Chromium-based browsers.
Affected products
- Google Chrome prior to 86.0.4240.183
- Google V8 Engine
- Microsoft Edge
- Opera Opera
Timeline
- 2020-11-02: patched: Stable channel update for desktop released (86.0.4240.183)
- 2021-11-03: disclosed: Published in NVD and added to CISA KEV catalog
- 2021-11-03: kev added