ZeroHour

CVE-2021-21220

KEV PoC ×2mass1

Out-of-Bounds Write in Google Chrome V8 Enables Heap Corruption and Potential RCE

CISA: Google Chromium V8 Improper Input Validation Vulnerability

CVSS 3.1
8.8 high
EPSS
70%p99
Published
()
KEV added
AI analysis

CVE-2021-21220 is an insufficient input validation flaw (CWE-787, out-of-bounds write) in the V8 JavaScript engine used by Google Chrome, affecting Chrome versions prior to 89.0.4389.128. A remote attacker can trigger the flaw by persuading a user to open a crafted HTML page, causing V8 to mishandle untrusted input and corrupt the heap. Successful exploitation can lead to heap corruption and potential remote code execution in the browser, with no privileges required beyond user interaction. The flaw affects Chrome and Chromium-based builds that ship the vulnerable V8 engine, including Fedora's Chromium package. It was exploited in the wild as a zero-day before the April 2021 fix, is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), and related reporting notes attacks using the disclosed Chromium exploit against WeChat users.

What to do: Update Google Chrome to version 89.0.4389.128 or later (ideally the current stable release); Fedora users should apply the updated Chromium package from their distribution repositories. Because the flaw is in the CISA KEV catalog, federal and KEV-bound organizations must patch per vendor instructions, and users of other Chromium-based browsers should verify their underlying V8/Chromium version has incorporated the fix.

Affected
google chrome (Chromium V8 engine)prior to 89.0.4389.128
fedoraproject fedora (Chromium/V8 build)
Estimated exposure
massbillions of Chrome users (Chrome holds roughly 60%+ of desktop browser market share) — Chrome is the world's dominant desktop browser with an estimated installed base of well over a billion users, and the vulnerable V8 engine is shared across Chromium builds, so essentially every up-to-date-until-April-2021 Chrome…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlefedoraproject
Products
chrome, fedora
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news