Skip to content
COOEY

EXPOSURES › CVE-2021-21148

CVE-2021-21148

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-21148 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

A heap buffer overflow in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.

This vulnerability enabled remote code execution through a crafted HTML page, posing a severe risk to any organization relying on Chromium-based browsers like Chrome, Edge, or Opera. DIBs must ensure these browsers are patched immediately, as unpatched instances could be exploited in the wild to compromise systems and violate compliance requirements. The failure highlights the critical need for timely patch management of widely deployed software.

Shame score — A known heap buffer overflow in a widely used engine was actively exploited in the wild, demonstrating a failure to patch a critical vulnerability before it was weaponized.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Widespread acknowledgement of the vulnerability and its impact, with no positive commentary.
cooey ↗ severe-fallout -0.80
Neutral reporting, but highlighting the broad impact.
"This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera."
www.cvefind.com ↗ severe-fallout +0.00
Neutral, factual listing.
time.com ↗ severe-fallout +0.00
Irrelevant content.
chromereleases.googleblog.com ↗ severe-fallout +0.00
Irrelevant content.
xposedornot.com ↗ severe-fallout +0.00
Irrelevant content.
securityonline.info ↗ severe-fallout +0.00
Irrelevant content.
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized