← back
CVE-2021-21224

CVE-2021-21224

CVSS 8.8 HIGHEPSS 57.7%● KEVCWE-843
In short

A type confusion bug in Chrome's V8 engine allowed attackers to run malicious code inside the browser's sandbox by tricking it with a specially crafted webpage. This could let attackers steal data or compromise your computer.

Technical detail

Type confusion vulnerability in V8 (CWE-843) where incorrect type handling enables arbitrary code execution within the Chrome sandbox. Attack vector is remote via crafted HTML; requires user to visit a malicious webpage. Pre-conditions: victim uses vulnerable Chrome version <90.0.4430.85. Impact includes sandbox escape and arbitrary code execution.

Summary generated and translated by AI from the official description.
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Google · Chrome

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →