Executive brief
A use-after-free vulnerability in the Google Chromium V8 engine allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. The flaw was reported as being exploited in the wild at the time of disclosure.
Affected products
- Google Chrome prior to 94.0.4606.71
- Google Chromium V8 Engine
- Microsoft Edge
- Opera Opera
Timeline
- 2021-09-30: patched: Stable channel update for desktop 94.0.4606.71 released.
- 2021-11-03: disclosed: Vulnerability published.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2021-11-03: exploited: Reported as exploited in the wild.