ZeroHour

CVE-2021-30563

KEVmass

Type Confusion in Google Chrome V8 Engine Exploited in the Wild

CISA: Google Chromium V8 Type Confusion Vulnerability

CVSS 3.1
8.8 high
EPSS
9%p95
Published
()
KEV added
AI analysis

CVE-2021-30563 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine used by Google Chrome and Chromium. A remote attacker triggers it by luring a user to a crafted HTML page, where mistyped objects in V8 can corrupt the heap. Successful exploitation can lead to heap corruption that the attacker can leverage for code execution within the browser renderer process. Anyone running Google Chrome prior to 91.0.4472.164, or a Chromium-based browser built on the vulnerable V8, is affected. The flaw is confirmed exploited in the wild: it was patched as an actively exploited Chrome zero-day and was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03.

What to do: Upgrade Google Chrome to 91.0.4472.164 or later immediately (verify the installed version via Help > About Chrome); users of Chromium-based browsers should install their vendor's update containing the patched V8. Because in-the-wild exploitation is confirmed (CISA KEV), treat this as urgent patching and confirm auto-update has actually completed rather than assuming it.

Affected
google chromeprior to 91.0.4472.164
google chromium (V8 JavaScript engine)prior to 91.0.4472.164
Estimated exposure
mass≈3 billion+ Chrome/Chromium installs and users worldwide — Chrome is the dominant desktop browser with roughly 65% browser share and billions of users, so at disclosure most internet users ran the affected V8, though Chrome's silent auto-update rapidly shrinks the unpatched population.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
google
Products
chrome
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news