EXPOSURES › CVE-2021-21220
CVE-2021-21220
HIGH ⌖ ON CISA KEV · EXPLOITEDA remote attacker could exploit heap corruption via a crafted HTML page in Google Chromium V8 to execute arbitrary code.
This improper input validation vulnerability in the Chromium V8 engine allows remote code execution through heap corruption, affecting major browsers like Chrome and Edge. DIB organizations must ensure their browsers are patched immediately, as this KEV-listed flaw was actively exploited in the wild and represents a severe compliance risk under NIST 800-171 for unpatched software.
Shame score — A critical RCE flaw in a foundational browser engine was actively exploited in the wild and listed in CISA's KEV catalog, indicating severe negligence in patching and vulnerability management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |