Skip to content
COOEY

EXPOSURES › CVE-2021-38003

CVE-2021-38003

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-38003 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatchedrce

A memory corruption bug in Google Chromium V8's JSON.stringify function leaked internal data to script code, causing corruption across multiple Chromium-based browsers.

This memory corruption vulnerability in the Chromium V8 engine allowed internal values to leak into script code, leading to memory corruption in browsers like Chrome, Edge, and Opera. DIB organizations must care because unpatched Chromium-based browsers could be exploited for remote code execution, violating CMMC/NIST 800-171 requirements for patch management and system integrity. Organizations should enforce strict patching cycles for all Chromium-based endpoints and monitor for exploitation attempts.

Shame score — A memory corruption bug in a widely used engine was actively exploited in the wild (KEV), indicating avoidable negligence in patching and vulnerability management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

SENTIMENT · TRUSTED SOURCES
synthesis negative -0.50
Acknowledged, but no strong condemnation.
cooey ↗ negative -0.50
Neutral reporting of facts.
"Google Chromium V8 Engine has a bug in JSON.stringify..."
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized