CVE-2021-30632
KEVmassOut-of-Bounds Write in Google Chrome V8 JavaScript Engine (CVE-2021-30632)
CISA: Google Chromium V8 Out-of-Bounds Write Vulnerability
CVE-2021-30632 is an out-of-bounds write (CWE-787) in V8, the JavaScript engine used by Google Chrome and other Chromium-based browsers, affecting Chrome versions prior to 93.0.4577.82. A remote attacker can trigger the flaw by luring a user to a crafted HTML page, since the vulnerable code is reached when the browser processes attacker-supplied web content (user interaction is required per the CVSS vector). Successful exploitation corrupts the heap and can allow the attacker to execute code within the browser process, with high impact on confidentiality, integrity, and availability. Anyone running an unpatched version of Chrome or Chromium — including Fedora's packaged Chromium/Chrome — is affected. The vulnerability was known to be actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, EPSS assigns a 63.2% probability of exploitation within 30 days, and it was among the 15+ Chrome zero-days Google patched during 2021, though no public proof-of-concept is known.
What to do: Update Google Chrome to 93.0.4577.82 or later on all platforms and restart the browser so the new V8 is loaded; on Fedora, apply the updated chromium/chrome packages through the normal update channel. Because this flaw is on the CISA KEV catalog, federal and critical-infrastructure teams should patch per vendor instructions on the required timeline; defenders should also verify no unmanaged or Kiosk-style Chromium installs remain below the fixed version.
| google chrome | all versions prior to 93.0.4577.82 |
| google chromium (V8 JavaScript engine) | V8 as shipped in Chromium builds prior to the Chrome 93.0.4577.82 fix |
| fedoraproject fedora (packaged Chromium/Chrome) | Fedora packages containing the affected V8 engine, prior to the vendor update |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- Affected
- Google Chromium V8
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- googlefedoraproject
- Products
- chrome, fedora
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H