Vulnerability record · CVE-2021-30563 · published 3 August 2021
CVE-2021-30563: Google Chrome V8 type confusion allows heap corruption
Google · Chrome
Google Chrome before 91.0.4472.164 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and potentially corrupt the heap, which matters because the browser is widely deployed and the flaw was exploited in the wild.
Description
Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is confirmed exploited in the wild per CISA KEV and has a high CVSS score, though it requires user interaction to trigger.
What it is
Google Chrome before 91.0.4472.164 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and potentially corrupt the heap, which matters because the browser is widely deployed and the flaw was exploited in the wild.
Impact
An attacker who gets the victim to load a crafted page can potentially achieve heap corruption, which can lead to code execution or a crash in the browser process. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
The flaw is reached over the network by rendering a crafted HTML page, so no authentication is required. The CVSS vector requires user interaction (UI:R), meaning the victim must open or visit the malicious page.
Exploitation
CVE-2021-30563 is listed in CISA's Known Exploited Vulnerabilities catalog with a 2021-11-17 remediation due date, confirming exploitation in the wild. EPSS gives a 30-day probability of 0.08928 (94.9th percentile), indicating elevated likelihood.
What to do
- Update Google Chrome to 91.0.4472.164 or later, and apply the vendor's stable channel update.
- Track and enforce browser version compliance across endpoints so older Chrome builds are removed.
- Enable automatic updates for Chrome where policy allows.
- Restrict or monitor access to untrusted web content on high-value systems.
- Review CISA KEV guidance and confirm remediation by the listed due date.
Detection
- Monitor for Chrome processes spawning unexpected child processes or writing unusual files after browsing.
- Alert on crashes or renderer process terminations consistent with heap corruption in Chrome.
- Hunt for network requests to known malicious or newly registered domains delivering exploit pages.
- Check endpoint inventories for Chrome versions below 91.0.4472.164.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-30563 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Google Chromium V8 Type Confusion Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://chromereleases.googleblog.com/2021/07/stable-channel-update-for-desktop.html | Release NotesVendor Advisory |
| https://crbug.com/1228407 | Permissions RequiredVendor Advisory |
| https://chromereleases.googleblog.com/2021/07/stable-channel-update-for-desktop.html | Release NotesVendor Advisory |
| https://crbug.com/1228407 | Permissions RequiredVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30563 | US Government Resource |
Track CVE-2021-30563 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-30563), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.