Junglewise Threat Intelligence

CVE-2021-21148: Google Chromium V8 Heap Buffer Overflow Vulnerability

CVE-2021-21148 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Google Chromium V8, Microsoft Edge, Google Chrome. Vendors: Google, Opera, Microsoft.

Executive brief

A heap buffer overflow vulnerability exists in the Google Chromium V8 engine. A remote attacker can exploit this via a specially crafted HTML page to cause heap corruption, potentially leading to arbitrary code execution.

Affected products

  • Google Chrome prior to 88.0.4324.150
  • Google V8 Engine prior to 88.0.4324.150
  • Microsoft Edge
  • Opera Opera

Timeline

  • 2021-02-04: patched: Stable channel update for desktop 88.0.4324.150 released.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: disclosed: Publicly published.

Related threats