Junglewise Threat Intelligence

CVE-2021-38003: Google Chromium V8 Memory Corruption Vulnerability

CVE-2021-38003 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Google Chromium V8, Google Chrome. Vendors: Google.

Executive brief

Google Chromium V8 Engine contains a memory corruption vulnerability due to an inappropriate implementation in JSON.stringify that allows the internal TheHole value to leak to script code. A remote attacker can exploit this heap corruption via a crafted HTML page, potentially affecting all Chromium-based browsers.

Affected products

  • Google Chrome prior to 95.0.4638.69
  • Google V8 Engine

Timeline

  • 2021-10-28: patched: Stable channel update for desktop released (95.0.4638.69)
  • 2021-11-03: disclosed: Vulnerability published and added to CISA KEV catalog
  • 2021-11-03: kev added
  • 2021-11-03: exploited: Reported as exploited in the wild in CISA KEV catalog

Related threats