CVE-2021-4102 is a critical use-after-free vulnerability in the V8 JavaScript engine affecting Google Chrome prior to version 96.0.4664.110. This flaw allows a remote attacker to achieve heap corruption and potentially execute arbitrary code by enticing a user to visit a specially crafted HTML page. Rated with a CVSS score of 8.8 (HIGH), it requires user interaction but can lead to high impact on confidentiality, integrity, and availability. Importantly, this vulnerability has been actively exploited in the wild as a zero-day, garnering significant media attention and community discussion, despite a lack of public exploit intelligence tools like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 96.0.4664.110CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.