Junglewise Threat Intelligence

CVE-2021-30632: Google Chromium V8 Out-of-Bounds Write Vulnerability

CVE-2021-30632 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Google Chromium V8, Google Chrome, Microsoft Edge. Vendors: Google, Opera, Microsoft.

Executive brief

An out-of-bounds write vulnerability in the Google Chromium V8 engine allows a remote attacker to exploit heap corruption via a specially crafted HTML page. This flaw impacts Google Chrome and other Chromium-based browsers such as Microsoft Edge and Opera.

Affected products

  • Google Chrome prior to 93.0.4577.82
  • Google V8 Engine
  • Microsoft Edge
  • Opera Opera

Timeline

  • 2021-09-13: patched: Google released Chrome version 93.0.4577.82 to address this vulnerability.
  • 2021-11-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: disclosed: Publicly disclosed via NVD and CISA.

Related threats