CVE-2021-21220
KEV PoC ×2mass1Out-of-Bounds Write in Google Chrome V8 Enables Heap Corruption and Potential RCE
CISA: Google Chromium V8 Improper Input Validation Vulnerability
CVE-2021-21220 is an insufficient input validation flaw (CWE-787, out-of-bounds write) in the V8 JavaScript engine used by Google Chrome, affecting Chrome versions prior to 89.0.4389.128. A remote attacker can trigger the flaw by persuading a user to open a crafted HTML page, causing V8 to mishandle untrusted input and corrupt the heap. Successful exploitation can lead to heap corruption and potential remote code execution in the browser, with no privileges required beyond user interaction. The flaw affects Chrome and Chromium-based builds that ship the vulnerable V8 engine, including Fedora's Chromium package. It was exploited in the wild as a zero-day before the April 2021 fix, is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), and related reporting notes attacks using the disclosed Chromium exploit against WeChat users.
What to do: Update Google Chrome to version 89.0.4389.128 or later (ideally the current stable release); Fedora users should apply the updated Chromium package from their distribution repositories. Because the flaw is in the CISA KEV catalog, federal and KEV-bound organizations must patch per vendor instructions, and users of other Chromium-based browsers should verify their underlying V8/Chromium version has incorporated the fix.
| google chrome (Chromium V8 engine) | prior to 89.0.4389.128 |
| fedoraproject fedora (Chromium/V8 build) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- Affected
- Google Chromium V8
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- googlefedoraproject
- Products
- chrome, fedora
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H