Vulnerability record · CVE-2021-21220 · published 26 April 2021
CVE-2021-21220: Google Chrome V8 out-of-bounds write via crafted HTML page
Google · Chrome
Chrome's V8 JavaScript engine fails to properly validate untrusted input, leading to an out-of-bounds write and heap corruption. The flaw affects Chrome before 89.0.4389.128 and is remotely reachable through a crafted HTML page, making it a serious browser-engine memory-safety issue.
Description
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a remotely reachable memory-corruption flaw in a widely deployed browser, listed in CISA KEV with public exploit references and very high EPSS, though it requires user interaction.
What it is
Chrome's V8 JavaScript engine fails to properly validate untrusted input, leading to an out-of-bounds write and heap corruption. The flaw affects Chrome before 89.0.4389.128 and is remotely reachable through a crafted HTML page, making it a serious browser-engine memory-safety issue.
Impact
An attacker can corrupt the heap and potentially achieve remote code execution in the browser process, with high impact to confidentiality, integrity and availability.
Attack surface
Reached over the network by rendering a crafted HTML page; no privileges are required but user interaction (opening the page) is needed per the CVSS vector.
Exploitation
Listed in CISA KEV with a 2021-11-03 addition and a 2021-11-17 remediation due date, and EPSS shows a 30-day probability of 0.70435 (99.354 percentile); references carry Exploit tags, indicating public exploit material exists.
What to do
- Update Chrome to 89.0.4389.128 or later, and apply the corresponding Fedora and Gentoo updates.
- Enforce automatic browser updates and verify deployed versions across endpoints.
- Restrict or sandbox browsing where feasible and block known malicious or untrusted sites.
- Monitor for exploitation attempts and treat unpatched Chrome as a priority remediation item.
Detection
- Hunt for Chrome versions below 89.0.4389.128 in asset inventories and endpoint telemetry.
- Monitor browser crash reports and renderer process crashes consistent with heap corruption.
- Watch network and proxy logs for delivery of exploit pages matching known V8 exploit patterns.
- Correlate endpoint process behavior for suspicious child processes spawned from Chrome renderers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-21220 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Google Chromium V8 Improper Input Validation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-21220 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21220), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.