EXPOSURES › CVE-2021-37975
CVE-2021-37975
HIGH ⌖ ON CISA KEV · EXPLOITEDA use-after-free vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
This use-after-free flaw in the Chromium V8 engine enabled remote code execution through malicious web pages, impacting Google Chrome, Microsoft Edge, and Opera. DIB organizations must ensure their browsers are patched promptly, as unpatched instances could lead to data breaches or ransomware entry. The vulnerability was actively exploited in the wild, highlighting the risk of relying on unpatched software.
Shame score — The vulnerability was actively exploited in the wild and affected widely used browsers, demonstrating a significant exposure to remote attackers despite being a known issue.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
"Google Chromium V8 Engine contains a use-after-free vulnerability..."
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |