CVE-2021-30563
KEVmassType Confusion in Google Chrome V8 Engine Exploited in the Wild
CISA: Google Chromium V8 Type Confusion Vulnerability
CVE-2021-30563 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine used by Google Chrome and Chromium. A remote attacker triggers it by luring a user to a crafted HTML page, where mistyped objects in V8 can corrupt the heap. Successful exploitation can lead to heap corruption that the attacker can leverage for code execution within the browser renderer process. Anyone running Google Chrome prior to 91.0.4472.164, or a Chromium-based browser built on the vulnerable V8, is affected. The flaw is confirmed exploited in the wild: it was patched as an actively exploited Chrome zero-day and was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03.
What to do: Upgrade Google Chrome to 91.0.4472.164 or later immediately (verify the installed version via Help > About Chrome); users of Chromium-based browsers should install their vendor's update containing the patched V8. Because in-the-wild exploitation is confirmed (CISA KEV), treat this as urgent patching and confirm auto-update has actually completed rather than assuming it.
| google chrome | prior to 91.0.4472.164 |
| google chromium (V8 JavaScript engine) | prior to 91.0.4472.164 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- Affected
- Google Chromium V8
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Products
- chrome
- Weakness
- CWE-843
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H