EXPOSURES › CVE-2021-30632
CVE-2021-30632
HIGH ⌖ ON CISA KEV · EXPLOITEDAn out-of-bounds write vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
This vulnerability enabled remote code execution through heap corruption, posing a severe risk to organizations relying on Chromium-based browsers like Chrome and Edge. DIBs must ensure their browsers are patched immediately, as unpatched instances could be exploited in the wild to compromise systems and violate compliance requirements. The failure highlights the critical need for timely patch management and monitoring of actively exploited vulnerabilities.
Shame score — The vulnerability was actively exploited in the wild (KEV) and linked to ransomware campaigns, demonstrating severe negligence in patching and exposure to widespread attacks.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
"Google Chromium V8 Engine contains an out-of-bounds write vulnerability"
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |