Junglewise Threat Intelligence

CVE-2021-37975: Google Chromium V8 Use-After-Free Vulnerability

CVE-2021-37975 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Google Chromium V8, Google Chrome, Microsoft Edge. Vendors: Google, Opera, Microsoft.

Executive brief

A use-after-free vulnerability in the Google Chromium V8 engine allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. The flaw was reported as being exploited in the wild at the time of disclosure.

Affected products

  • Google Chrome prior to 94.0.4606.71
  • Google Chromium V8 Engine
  • Microsoft Edge
  • Opera Opera

Timeline

  • 2021-09-30: patched: Stable channel update for desktop 94.0.4606.71 released.
  • 2021-11-03: disclosed: Vulnerability published.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: exploited: Reported as exploited in the wild.

Related threats