CVE-2021-21224KEV · OVERDUE

Google Chromium V8 Type Confusion Vulnerability

High · published April 26, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 8.8. It is confirmed in active exploitation. It sits in the 99.7th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
8.8
EPSS
84%
Percentile
99.7
In the wild
Confirmed
What it is

🚨 A crafted HTML page can turn users' browsers into playgrounds for attackers! This type confusion flaw in Chrome’s V8 engine before version 90.0.4430.85 allows for remote code execution, making it a high-risk discovery! ⚡ Think of your browser as a high-security museum where each exhibit is carefully monitored. Now imagine a careless curator mixes up the labels—suddenly, an exhibit on ancient artifacts becomes a live demo of cutting-edge technology, and anyone can waltz in undetected! An attacker could exploit this vulnerability to execute arbitrary code within the browser's sandbox environment, potentially stealing sensitive data, installing malware, or compromising user accounts. The consequences could range from personal data theft to wider network breaches, making this a situation you definitely want to avoid!

Put simply

Think of your browser as a high-security museum where each exhibit is carefully monitored. Now imagine a careless curator mixes up the labels—suddenly, an exhibit on ancient artifacts becomes a live demo of cutting-edge technology, and anyone can waltz in undetected! This vulnerability stems from a type confusion issue in the V8 JavaScript engine, allowing attackers to manipulate the type system and execute arbitrary code with the privileges of the user running the browser. Essentially, it's a bug that allows malicious code to bypass sandbox protections in Chrome.

What to do

An attacker could exploit this vulnerability to execute arbitrary code within the browser's sandbox environment, potentially stealing sensitive data, installing malware, or compromising user accounts. The consequences could range from personal data theft to wider network breaches, making this a situation you definitely want to avoid! Update your Google Chrome to version 90.0.4430.85 or later immediately to patch this vulnerability. Regularly check for updates to ensure your browser is secure. Additionally, consider implementing strict content security policies to further mitigate risks! You’ve got this! Stay vigilant, keep your software updated, and you'll be a security hero in no time! 🛡️

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.84173 · 99.7th percentile
Published
2021-04-26T16:56Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 25 AUG 00:01Z
    EPSS moved 56% → 84%
    epss
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 26 APR 16:56Z
    Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
    cvelistv5