Executive brief
Google Chromium V8 Engine contains a memory corruption vulnerability due to an inappropriate implementation in JSON.stringify that allows the internal TheHole value to leak to script code. A remote attacker can exploit this heap corruption via a crafted HTML page, potentially affecting all Chromium-based browsers.
Affected products
- Google Chrome prior to 95.0.4638.69
- Google V8 Engine
Timeline
- 2021-10-28: patched: Stable channel update for desktop released (95.0.4638.69)
- 2021-11-03: disclosed: Vulnerability published and added to CISA KEV catalog
- 2021-11-03: kev added
- 2021-11-03: exploited: Reported as exploited in the wild in CISA KEV catalog