Junglewise Threat Intelligence

CVE-2021-21220: Google Chromium V8 Improper Input Validation Vulnerability

CVE-2021-21220 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Google Chromium V8, Google Chrome, Microsoft Edge, Opera Software Opera. Vendors: Google, Microsoft, Opera Software.

Executive brief

Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This flaw can lead to arbitrary code execution within the context of the browser process.

Affected products

  • Google Chrome prior to 89.0.4389.128
  • Google V8 prior to 89.0.4389.128
  • Microsoft Edge
  • Opera Software Opera

Timeline

  • 2021-04-13: patched: Stable Channel Update for Desktop 89.0.4389.128
  • 2021-11-03: disclosed: Published in NVD
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Confirmed exploited in the wild per CISA KEV catalog entry date.

Related threats