KEVIntel
8.8
CVSS
High

CVE-2021-21220

PUBLISHED

Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap...

Exploited in the wild PoC available Remote Low complexity
Vendor
Google
Product
Chrome
Published
Apr 26, 2021
EPSS

Automate This Intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.

Description

Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

cisa metasploit

Weaknesses (CWE)

CVSS Scores

CVSS v3.1 8.8 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2.0 6.8 Medium

AV:N/AC:M/Au:N/C:P/I:P/A:P

Exploitation Status

Exploited in the wild

Recorded 2021-11-03 00:00:00 UTC · CISA

Proof of concept available

Recorded 2021-09-15 03:11:41 UTC · GitHub

Known Exploited Vulnerability Sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA First 2021-11-03 00:00 UTC

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

security-dbg/CVE-2021-21220

github · Created 2021-09-15 03:11:41 UTC · 9 stars

chrome_cve_2021_21220_v8_insufficient_validation

metasploit · Created Unknown

Metasploit module for CVE-2021-21220

Timeline

  • Detected by Metasploit

  • Added to KEVIntel

  • Proof of Concept Exploit Available

  • CVE Published to Public

  • CVE ID Reserved