Skip to content
COOEY

EXPOSURES › CVE-2021-30551

CVE-2021-30551

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-30551 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.

This vulnerability enabled remote code execution through heap corruption, impacting Google Chrome, Microsoft Edge, and Opera. DIB organizations must ensure their browsers are patched immediately, as unpatched instances could lead to data breaches or ransomware entry. The fact that it was actively exploited in the wild underscores the critical need for timely patching and strict browser hardening.

Shame score — A known, actively exploited vulnerability in a widely used browser engine that could lead to remote code execution, representing a significant avoidable risk for organizations relying on Chromium-based browsers.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Significant fallout due to widespread impact and CISA's designation as actively exploited.
cvefeed.io ↗ severe-fallout -1.00
Strongly negative, highlighting active exploitation.
"Because each KEV entry carries direct evidence of active exploitation, the catalog is one of the highest-signal inputs for risk-based patch mana"
cooey ↗ severe-fallout -0.80
Neutral reporting, highlighting broad impact.
"This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera."
www.cvefind.com ↗ severe-fallout +0.00
Informational, no sentiment.
cvedb.shodan.io ↗ severe-fallout +0.00
Informational, no sentiment.
xposedornot.com ↗ severe-fallout +0.00
Informational, no sentiment.
app.opencve.io ↗ severe-fallout +0.00
Informational, no sentiment.
chromereleases.googleblog.com ↗ severe-fallout +0.00
Informational, no sentiment.
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized