CVE-2021-38003 is a critical vulnerability in Google Chrome's V8 JavaScript engine, affecting versions prior to 95.0.4638.69, including various Debian and Fedora distributions. This high-severity flaw (CVSS 8.8) allows a remote attacker to achieve heap corruption and potentially execute arbitrary code by enticing a user to visit a specially crafted HTML page. The vulnerability has been actively exploited as a zero-day in the wild, as confirmed by its presence in the KEV catalog and numerous media reports, despite a lack of public exploit code. Community discussion surrounding this CVE is exceptionally high, indicating significant attention from the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 95.0.4638.69CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.