CVE-2021-38003KEV · OVERDUE

Google Chromium V8 Memory Corruption Vulnerability

High · published November 23, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 8.8. It is confirmed in active exploitation. It sits in the 98.5th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
8.8
EPSS
39%
Percentile
98.5
In the wild
Confirmed
What it is

🚨 A crafty crafted HTML page is the key to exploiting this heap corruption in Chrome – and it's already being exploited! 🔥 Think of it like a restaurant where an attacker slips a poison ingredient into the chef's secret sauce — the dish ends up tasting fine until it causes chaos later on. This vulnerability allows bad actors to manipulate memory like a chef tinkering with a recipe, leading to unexpected results. If exploited, this vulnerability could allow an attacker to execute arbitrary code on your system, potentially accessing personal data, altering settings, or even controlling your browser remotely. This can be absolutely devastating for users, as the attacker can fully compromise the system without the user’s knowledge!

Put simply

Think of it like a restaurant where an attacker slips a poison ingredient into the chef's secret sauce — the dish ends up tasting fine until it causes chaos later on. This vulnerability allows bad actors to manipulate memory like a chef tinkering with a recipe, leading to unexpected results. This vulnerability in the V8 engine of Google Chrome allows remote attackers to exploit heap corruption through specially crafted HTML content, leading to potential code execution.

What to do

If exploited, this vulnerability could allow an attacker to execute arbitrary code on your system, potentially accessing personal data, altering settings, or even controlling your browser remotely. This can be absolutely devastating for users, as the attacker can fully compromise the system without the user’s knowledge! Immediately update Chrome to version 95.0.4638.69 or later to patch this vulnerability. It's crucial to regularly check for updates to keep your browser fortified against such sneaky attacks! You've got this! By following these steps, you'll be a security hero, keeping your browsing safe and sound! 🦸

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.38573 · 98.5th percentile
Published
2021-11-23T21:30Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 23 NOV 21:30Z
    Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…
    cvelistv5
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev