Executive brief
Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This flaw can lead to arbitrary code execution within the context of the browser process.
Affected products
- Google Chrome prior to 89.0.4389.128
- Google V8 prior to 89.0.4389.128
- Microsoft Edge
- Opera Software Opera
Timeline
- 2021-04-13: patched: Stable Channel Update for Desktop 89.0.4389.128
- 2021-11-03: disclosed: Published in NVD
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Confirmed exploited in the wild per CISA KEV catalog entry date.