ZeroHour

CVE-2021-21148

KEVmass1

Heap Buffer Overflow in Google Chrome/Chromium V8 (CVE-2021-21148)

CISA: Google Chromium V8 Heap Buffer Overflow Vulnerability

CVSS 3.1
8.8 high
EPSS
20%p97
Published
()
KEV added
AI analysis

CVE-2021-21148 is a heap buffer overflow (out-of-bounds write, CWE-787) in the V8 JavaScript engine used by Google Chrome and Chromium. A remote attacker triggers it by getting a user to open a crafted HTML page, so user interaction is required, but no privileges or special access are needed. Successful exploitation corrupts the heap and can allow the attacker to run code within the browser, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). All Chrome/Chromium builds prior to 88.0.4324.150 are affected, including the chromium packages shipped in Fedora and Debian. Google patched the flaw in an emergency update for what headlines described as a Chrome zero-day, and its inclusion in the CISA Known Exploited Vulnerabilities catalog (added 2021-11-03) confirms exploitation in the wild, despite no public PoC; EPSS estimates a 20% probability of exploitation over the next 30 days (97th percentile).

What to do: Upgrade Google Chrome/Chromium to 88.0.4324.150 or later on all endpoints, and install the updated chromium packages from Fedora and Debian. Verify fleet-wide browser versions, since a single user opening a malicious page is enough for compromise, and confirm auto-update is enabled on managed browsers.

Affected
google chrome / chromium (V8 engine)all builds prior to 88.0.4324.150
fedoraproject fedora (chromium package)chromium builds prior to the updated V8 fix (specific package version not provided in available data)
debian linux (chromium package)chromium builds prior to the updated V8 fix (specific package version not provided in available data)
Estimated exposure
mass≈3 billion+ users (Chrome's global install base; essentially every Chrome/Chromium build before 88.0.4324.150 was vulnerable) — Chrome's installed base across Windows, macOS, and Linux, plus Chromium-derived browser packages in Fedora and Debian, is estimated in the billions from public browser market-share and usage statistics, making this a mass-scale exposure.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlefedoraprojectdebian
Products
chrome, fedora, debian linux
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news