ZeroHour

CVE-2021-30632

KEVmass

Out-of-Bounds Write in Google Chrome V8 JavaScript Engine (CVE-2021-30632)

CISA: Google Chromium V8 Out-of-Bounds Write Vulnerability

CVSS 3.1
8.8 high
EPSS
63%p99
Published
()
KEV added
AI analysis

CVE-2021-30632 is an out-of-bounds write (CWE-787) in V8, the JavaScript engine used by Google Chrome and other Chromium-based browsers, affecting Chrome versions prior to 93.0.4577.82. A remote attacker can trigger the flaw by luring a user to a crafted HTML page, since the vulnerable code is reached when the browser processes attacker-supplied web content (user interaction is required per the CVSS vector). Successful exploitation corrupts the heap and can allow the attacker to execute code within the browser process, with high impact on confidentiality, integrity, and availability. Anyone running an unpatched version of Chrome or Chromium — including Fedora's packaged Chromium/Chrome — is affected. The vulnerability was known to be actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, EPSS assigns a 63.2% probability of exploitation within 30 days, and it was among the 15+ Chrome zero-days Google patched during 2021, though no public proof-of-concept is known.

What to do: Update Google Chrome to 93.0.4577.82 or later on all platforms and restart the browser so the new V8 is loaded; on Fedora, apply the updated chromium/chrome packages through the normal update channel. Because this flaw is on the CISA KEV catalog, federal and critical-infrastructure teams should patch per vendor instructions on the required timeline; defenders should also verify no unmanaged or Kiosk-style Chromium installs remain below the fixed version.

Affected
google chromeall versions prior to 93.0.4577.82
google chromium (V8 JavaScript engine)V8 as shipped in Chromium builds prior to the Chrome 93.0.4577.82 fix
fedoraproject fedora (packaged Chromium/Chrome)Fedora packages containing the affected V8 engine, prior to the vendor update
Estimated exposure
mass≈ billions of users (Chrome is the world's most widely used browser, with roughly 3+ billion installs; at disclosure time most installs had not yet reached… — Chrome's dominant desktop-browser market share (~60-65%) and multi-billion user base, plus V8's reuse in Chromium-derived browsers and Fedora's Chromium packages, put potentially affected installations in the billions, though exploitation…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlefedoraproject
Products
chrome, fedora
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news