Executive brief
A type confusion vulnerability in the Google Chromium V8 engine allows a remote attacker to potentially execute arbitrary code or cause heap corruption via a specially crafted HTML page. This vulnerability affects Google Chrome and other Chromium-based browsers such as Microsoft Edge and Opera.
Affected products
- Google Chrome prior to 91.0.4472.164
- Microsoft Edge
- Opera Opera
Timeline
- 2021-07-15: patched: Fixed in Chrome version 91.0.4472.164
- 2021-08-03: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild