Junglewise Threat Intelligence

CVE-2021-4102: Google Chromium V8 Use-After-Free Vulnerability

CVE-2021-4102 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-12-15

Technologies: Google Chromium V8, Microsoft Edge, Google Chrome. Vendors: Google, Opera, Microsoft.

Executive brief

A use-after-free vulnerability in the Google Chromium V8 engine allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability has been observed being exploited in the wild and affects multiple Chromium-based browsers.

Affected products

  • Google Chrome prior to 96.0.4664.110
  • Microsoft Edge
  • Opera Opera

Timeline

  • 2021-12-13: advisory: Google released stable channel update 96.0.4664.110 for desktop.
  • 2021-12-15: disclosed: Vulnerability published and added to CISA KEV catalog.
  • 2021-12-15: kev added
  • 2021-12-15: exploited: Reported as exploited in the wild.

Related threats