Executive brief
A use-after-free vulnerability in the Google Chromium V8 engine allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability has been observed being exploited in the wild and affects multiple Chromium-based browsers.
Affected products
- Google Chrome prior to 96.0.4664.110
- Microsoft Edge
- Opera Opera
Timeline
- 2021-12-13: advisory: Google released stable channel update 96.0.4664.110 for desktop.
- 2021-12-15: disclosed: Vulnerability published and added to CISA KEV catalog.
- 2021-12-15: kev added
- 2021-12-15: exploited: Reported as exploited in the wild.