ZeroHour

CVE-2021-4102

KEVmass2

Use-After-Free Zero-Day in Google Chrome's V8 JavaScript Engine

CISA: Google Chromium V8 Use-After-Free Vulnerability

CVSS 3.1
8.8 high
EPSS
8%p94
Published
()
KEV added
AI analysis

CVE-2021-4102 is a use-after-free (CWE-416) in the V8 JavaScript engine of Google Chrome, fixed in Chrome 96.0.4664.110. It is triggered remotely when a user is lured to a crafted HTML page (per the CVSS vector, network attack vector with required user interaction), allowing the attacker to trigger heap corruption in the browser process. Successful exploitation could give the attacker control over corrupted heap memory with high confidentiality, integrity, and availability impact, though no public proof-of-concept is known. Anyone running Google Chrome prior to 96.0.4664.110 is affected, and because CISA frames the flaw in Chromium's V8, Chromium-based browsers that had not yet merged the equivalent fix were also potentially exposed. The bug is a confirmed zero-day: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-12-15, and press coverage counts it as the 17th Chrome zero-day fixed in 2021.

What to do: Update Google Chrome to 96.0.4664.110 or later on all systems and restart the browser to load the patched engine; this satisfies CISA's required action to apply updates per vendor instructions. Inventory enterprise endpoints to confirm no clients remain below 96.0.4664.110, and users of Chromium-derived browsers should apply the corresponding vendor update as soon as it is released. Until patched, exercise caution with untrusted web links, as exploitation requires visiting attacker-controlled HTML content.

Affected
Google Chromeprior to 96.0.4664.110
Google Chromium (V8 engine)V8 component as designated by CISA; Chromium version range not specified in source data (fix shipped in Chrome 96.0.4664.110)
Estimated exposure
mass≈3 billion Chrome users/installs (Chrome is the world's dominant desktop browser) — Chrome's dominant global browser market share puts installed base in the billions, so effectively every Chrome deployment running a version below 96.0.4664.110 at disclosure was exposed, with unknown additional exposure among…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news