CVE-2021-21220: Google Chromium V8 Improper Input Validation Vulnerability
Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Other sources
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 89.0.4389.128
Event History
Frequently Asked Questions
What is CVE-2021-21220?
CVE-2021-21220 is a vulnerability in the Google Chromium V8 Engine that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Which software is affected by CVE-2021-21220?
Web browsers that utilize Chromium, including Google Chrome and Microsoft Edge, are affected by CVE-2021-21220.
What is the severity of CVE-2021-21220?
CVE-2021-21220 has a severity rating of 8.8, indicating a high severity.
How can the CVE-2021-21220 vulnerability be exploited?
CVE-2021-21220 can be exploited by a remote attacker through a crafted HTML page, potentially leading to heap corruption.
Are Fedora operating systems affected by CVE-2021-21220?
Yes, Fedora operating systems, specifically versions 32, 33, and 34, are affected by CVE-2021-21220.