CVE-2021-21220 is a critical heap corruption vulnerability in Google Chrome's V8 JavaScript engine, affecting versions prior to 89.0.4389.128, as well as Fedora-based Chrome distributions. With a CVSS score of 8.8 (HIGH), it allows remote attackers to achieve high impact on confidentiality, integrity, and availability through a crafted HTML page, requiring user interaction. This vulnerability is actively exploited in the wild, with public exploit modules available in Metasploit, and has garnered significant community and media attention, as indicated by its high EPSS and FAUCET scores.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 89.0.4389.128CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.