CVE-2021-37975KEV · OVERDUE

Google Chromium V8 Use-After-Free Vulnerability

High · published October 8, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 8.8. It is confirmed in active exploitation. It sits in the 98.3th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
8.8
EPSS
35%
Percentile
98.3
In the wild
Confirmed
What it is

🚨 A crafty HTML page can exploit a use-after-free vulnerability in Chrome, leading to potential heap corruption! ⚠️ Think of it like a restaurant serving food that was left on the counter too long; when a cook grabs it without checking, it can cause a stomach ache for diners. If the browser mishandles memory like this, attackers can craft a page that corrupts the system, causing chaos! An attacker could exploit this flaw to execute malicious code on a victim's machine. This means they could manipulate or steal sensitive information, install malware, or even take full control of the system! The consequences could be absolutely devastating, leaving users vulnerable and their data exposed.

Put simply

Think of it like a restaurant serving food that was left on the counter too long; when a cook grabs it without checking, it can cause a stomach ache for diners. If the browser mishandles memory like this, attackers can craft a page that corrupts the system, causing chaos! This use-after-free vulnerability in the V8 JavaScript engine of Google Chrome allows attackers to exploit memory that has already been freed, potentially leading to heap corruption and arbitrary code execution.

What to do

An attacker could exploit this flaw to execute malicious code on a victim's machine. This means they could manipulate or steal sensitive information, install malware, or even take full control of the system! The consequences could be absolutely devastating, leaving users vulnerable and their data exposed. Update Google Chrome immediately to version 94.0.4606.71 or later to close this security hole. Ensure your users are aware of the importance of keeping their browsers updated for optimal protection. You've got this! Patch up, update your browsers, and keep the digital world safe! 🛡️

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.34887 · 98.3th percentile
Published
2021-10-08T00:00Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 08 OCT 00:00Z
    Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
    cvelistv5