Junglewise Threat Intelligence

CVE-2021-21224: Google Chromium V8 Type Confusion Vulnerability

CVE-2021-21224 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Google Chromium V8, Microsoft Edge, Opera Software Opera, Google Chrome. Vendors: Google, Microsoft, Opera Software.

Executive brief

A type confusion vulnerability in the Google Chromium V8 engine allows a remote attacker to execute arbitrary code within a sandbox. The exploit is triggered when a user visits a specially crafted HTML page.

Affected products

  • Google Chrome prior to 90.0.4430.85
  • Microsoft Edge
  • Opera Software Opera

Timeline

  • 2021-04-20: patched: Stable channel update for desktop (90.0.4430.85) released.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: disclosed: NVD publication date.
  • exploited: Reported as exploited in the wild.

Related threats