CVE-2021-30632: Out of bounds write in V8
Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Other sources
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 93.0.4577.82
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2021-30632?
CVE-2021-30632 is a vulnerability in the Google Chromium V8 Engine that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Which software is affected by CVE-2021-30632?
Web browsers that utilize Chromium, including Google Chrome and Microsoft Edge, are affected by CVE-2021-30632.
How severe is CVE-2021-30632?
CVE-2021-30632 is classified as high severity and has a severity score of 8.8 out of 10.
How can I fix CVE-2021-30632?
To fix CVE-2021-30632, update your web browser to the latest version that includes a patch for this vulnerability.
Where can I find more information about CVE-2021-30632?
You can find more information about CVE-2021-30632 in the references provided: http://packetstormsecurity.com/files/172845/Chrome-JIT-Compiler-Type-Confusion.html, https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop.html, https://crbug.com/1247763.