Executive brief
A type confusion vulnerability in the Google Chromium V8 engine allows a remote attacker to execute arbitrary code within a sandbox. The exploit is triggered when a user visits a specially crafted HTML page.
Affected products
- Google Chrome prior to 90.0.4430.85
- Microsoft Edge
- Opera Software Opera
Timeline
- 2021-04-20: patched: Stable channel update for desktop (90.0.4430.85) released.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2021-11-03: disclosed: NVD publication date.
- exploited: Reported as exploited in the wild.