CVE-2021-30551 is a critical type confusion vulnerability in Google Chrome's V8 JavaScript engine, affecting versions prior to 91.0.4472.101, as well as Fedora Project's Chrome and Fedora. This flaw allows a remote attacker to achieve heap corruption and potentially execute arbitrary code by enticing a user to visit a specially crafted HTML page. With a CVSS score of 8.8 (High), it requires user interaction but has low attack complexity, leading to high impacts on confidentiality, integrity, and availability. Crucially, this vulnerability is confirmed to be actively exploited in the wild as a zero-day, as indicated by its presence in the KEV catalog and extensive media coverage. Despite the lack of public exploit code on platforms like Metasploit or ExploitDB, its high EPSS score and significant community discussion highlight the urgent need for patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 91.0.4472.101CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.