CVE-2021-21220KEV · OVERDUE

Google Chromium V8 Improper Input Validation Vulnerability

High · published April 26, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 8.8. It is confirmed in active exploitation. It sits in the 99.3th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
8.8
EPSS
70%
Percentile
99.3
In the wild
Confirmed
What it is

🔥 A single malicious HTML page is all it takes to exploit heap corruption in Google Chrome versions prior to 89.0.4389.128! ⚠️ Think of it like a restaurant that doesn't check the ingredients of the dishes being served. If a chef sneaks in a dangerous ingredient, it could spoil the whole meal, or worse, harm the diners! An attacker could send you a seemingly innocent link, leading to devastating consequences like crashing your browser, stealing data, or even taking control of your system! This kind of vulnerability is absolutely a nightmare for users who trust their browser to keep them safe.

Put simply

Think of it like a restaurant that doesn't check the ingredients of the dishes being served. If a chef sneaks in a dangerous ingredient, it could spoil the whole meal, or worse, harm the diners! This vulnerability arises from inadequate checks on untrusted input in Google Chrome's V8 JavaScript engine, allowing crafted HTML pages to manipulate memory and cause heap corruption.

What to do

An attacker could send you a seemingly innocent link, leading to devastating consequences like crashing your browser, stealing data, or even taking control of your system! This kind of vulnerability is absolutely a nightmare for users who trust their browser to keep them safe. Update Google Chrome immediately to version 89.0.4389.128 or later to patch this vulnerability. Encourage users to also enable auto-updates for seamless protection against future threats. 🛡️ You've got this! Stay proactive and keep your browser updated to ensure a safe browsing experience! 🚀

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.70435 · 99.3th percentile
Published
2021-04-26T00:00Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 26 APR 00:00Z
    Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a…
    cvelistv5