Skip to content
COOEY

EXPOSURES › CVE-2021-21220

CVE-2021-21220

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-21220 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatchedrce

A remote attacker could exploit heap corruption via a crafted HTML page in Google Chromium V8 to execute arbitrary code.

This improper input validation vulnerability in the Chromium V8 engine allows remote code execution through heap corruption, affecting major browsers like Chrome and Edge. DIB organizations must ensure their browsers are patched immediately, as this KEV-listed flaw was actively exploited in the wild and represents a severe compliance risk under NIST 800-171 for unpatched software.

Shame score — A critical RCE flaw in a foundational browser engine was actively exploited in the wild and listed in CISA's KEV catalog, indicating severe negligence in patching and vulnerability management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

SENTIMENT · TRUSTED SOURCES
synthesis neutral -0.20
Facts-only sources show no vendor condemnation
cooey ↗ neutral +0.00
Neutral
app.opencve.io ↗ neutral +0.00
Neutral
www.cvefind.com ↗ neutral +0.00
Neutral
xposedornot.com ↗ neutral +0.00
Neutral
Neutral
cvedb.shodan.io ↗ neutral +0.00
Neutral
stack.watch ↗ neutral +0.00
Neutral
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized