CVE-2021-37975
KEVmassUse-After-Free in Chromium V8 Engine Affects Chrome, Edge, and Opera
CISA: Google Chromium V8 Use-After-Free Vulnerability
CVE-2021-37975 is a use-after-free flaw (CWE-416) in the V8 JavaScript engine, the component at the core of the Chromium browser project that underpins most major desktop browsers. It is triggered remotely when a user visits or is redirected to an attacker-crafted HTML page, allowing the attacker to corrupt the browser's heap memory. A successful attacker could potentially leverage that heap corruption to execute code within the browser. Anyone using a Chromium-based browser — including Google Chrome, Microsoft Edge, Opera, and other Chromium derivatives — is affected until their vendor's fix is applied. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, and EPSS assigns a 34.9% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known.
What to do: Apply updates per vendor instructions immediately (CISA KEV required action): update Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers — including applications embedding Chromium/V8 — to the latest versions supplied by each vendor, and verify the installed version via the browser's about/settings page. Where patching must be delayed, restrict use of vulnerable browsers for untrusted websites and watch for follow-on vendor advisories, since the flaw is already being exploited in the wild.
| Google Chromium V8 (engine, as shipped in Chromium and downstream browsers) | — |
| Google Chrome (Chromium-based) | — |
| Microsoft Edge (Chromium-based) | — |
| Opera (Chromium-based) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- Affected
- Google Chromium V8
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- googlefedoraprojectdebian
- Products
- chrome, fedora, debian linux
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H