CVE-2021-30563: Type Confusion in V8
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Other sources
Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 91.0.4472.164
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2021-30563?
CVE-2021-30563 is a type confusion vulnerability in the Google Chromium V8 Engine that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Which software is affected by CVE-2021-30563?
Web browsers that utilize Chromium, including Google Chrome and Microsoft Edge, are affected by CVE-2021-30563.
How can CVE-2021-30563 be exploited?
CVE-2021-30563 can be exploited by a remote attacker via a crafted HTML page to potentially cause heap corruption.
What is the severity of CVE-2021-30563?
CVE-2021-30563 has a severity rating of 8.8 (high).
How can I fix CVE-2021-30563?
To fix CVE-2021-30563, update your web browser to the latest version provided by the vendor.