Junglewise Threat Intelligence

CVE-2021-30563: Google Chromium V8 Type Confusion Vulnerability

CVE-2021-30563 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Google Chromium V8, Google Chrome, Microsoft Edge. Vendors: Google, Opera, Microsoft.

Executive brief

A type confusion vulnerability in the Google Chromium V8 engine allows a remote attacker to potentially execute arbitrary code or cause heap corruption via a specially crafted HTML page. This vulnerability affects Google Chrome and other Chromium-based browsers such as Microsoft Edge and Opera.

Affected products

  • Google Chrome prior to 91.0.4472.164
  • Microsoft Edge
  • Opera Opera

Timeline

  • 2021-07-15: patched: Fixed in Chrome version 91.0.4472.164
  • 2021-08-03: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild

Related threats