ZeroHour

CVE-2021-30551

KEV PoC mass1

V8 Type Confusion Zero-Day in Google Chrome (CVE-2021-30551), Exploited in the Wild

CISA: Google Chromium V8 Type Confusion Vulnerability

CVSS 3.1
8.8 high
EPSS
65%p99
Published
()
KEV added
AI analysis

CVE-2021-30551 is a type confusion flaw (CWE-843) in the V8 JavaScript engine used by Google Chrome and Chromium, which can lead to heap corruption. An attacker triggers it by persuading a user to open a specially crafted HTML page — the browser bug requires user interaction but no privileges or authentication. Successful exploitation could allow a remote attacker to execute code or otherwise corrupt the browser process, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). Anyone running Google Chrome prior to 91.0.4472.101, including Chromium-based packages such as Fedora's chromium, is affected. The flaw was exploited as a zero-day before the fix was released, with Google attributing recent Chrome zero-day attacks including this issue to campaigns against Armenian targets linked to a commercial spyware vendor, and it is listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Update Google Chrome to 91.0.4472.101 or later (via chrome://settings/help) and update Fedora's chromium package to the patched build, then verify the version in chrome://version. Fedora/Chromium administrators should apply vendor updates per CISA KEV guidance. Until patched, treat web browsing as a risk vector and avoid opening untrusted links, since exploitation requires loading a crafted web page.

Affected
google chromeGoogle Chrome prior to 91.0.4472.101 (all platforms)
google chromium (V8 engine)Chromium builds with the vulnerable V8 engine, prior to the fix shipped in Chrome 91.0.4472.101
fedoraproject fedora (chromium package)Fedora chromium builds prior to the 91.0.4472.101-equivalent update
Estimated exposure
masshundreds of millions to billions of Chrome/Chromium installs worldwide (Chrome is the world's dominant browser) — Chrome's global market share of roughly 60-65% on desktop plus a very large Chromium-based install base implies an affected population in the hundreds of millions to billions before users updated to 91.0.4472.101 in mid-2021.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlefedoraproject
Products
chrome, fedora
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news