CVE-2021-30632 is an out-of-bounds write vulnerability in Google Chrome's V8 JavaScript engine, affecting versions prior to 93.0.4577.82, including Fedora Project distributions. This high-severity flaw (CVSS 8.8) allows a remote attacker to achieve heap corruption and potentially execute arbitrary code by enticing a user to visit a crafted HTML page. It is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, and has garnered significant community and media attention, despite no public exploit code being available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 93.0.4577.82CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.