Executive brief
Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability can lead to out-of-bounds writes and has been observed being exploited in the wild.
Affected products
- Google Chrome prior to 86.0.4240.198
- Google V8 Engine prior to 86.0.4240.198
- Microsoft Edge
- Opera Opera
Timeline
- 2020-11-11: patched: Stable channel update for desktop released (86.0.4240.198)
- 2021-01-08: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild