ZeroHour

CVE-2021-37975

KEVmass

Use-After-Free in Chromium V8 Engine Affects Chrome, Edge, and Opera

CISA: Google Chromium V8 Use-After-Free Vulnerability

CVSS 3.1
8.8 high
EPSS
35%p98
Published
()
KEV added
AI analysis

CVE-2021-37975 is a use-after-free flaw (CWE-416) in the V8 JavaScript engine, the component at the core of the Chromium browser project that underpins most major desktop browsers. It is triggered remotely when a user visits or is redirected to an attacker-crafted HTML page, allowing the attacker to corrupt the browser's heap memory. A successful attacker could potentially leverage that heap corruption to execute code within the browser. Anyone using a Chromium-based browser — including Google Chrome, Microsoft Edge, Opera, and other Chromium derivatives — is affected until their vendor's fix is applied. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, and EPSS assigns a 34.9% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known.

What to do: Apply updates per vendor instructions immediately (CISA KEV required action): update Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers — including applications embedding Chromium/V8 — to the latest versions supplied by each vendor, and verify the installed version via the browser's about/settings page. Where patching must be delayed, restrict use of vulnerable browsers for untrusted websites and watch for follow-on vendor advisories, since the flaw is already being exploited in the wild.

Affected
Google Chromium V8 (engine, as shipped in Chromium and downstream browsers)
Google Chrome (Chromium-based)
Microsoft Edge (Chromium-based)
Opera (Chromium-based)
Estimated exposure
massbillions of users — Chromium-based browsers account for roughly two-thirds of global desktop browser usage — Estimated from public browser market-share data, where Chrome alone holds on the order of 65% of desktop usage and Chromium derivatives such as Edge and Opera add substantially more, implying billions of installations worldwide.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlefedoraprojectdebian
Products
chrome, fedora, debian linux
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news