Vulnerability record · CVE-2021-30632 · published 8 October 2021
CVE-2021-30632: Google Chrome V8 out-of-bounds write via crafted HTML page
Google · Chrome
Google Chrome before 93.0.4577.82 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger heap corruption, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it has been used in real attacks.
Description
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8, CISA KEV listing and very high EPSS make this a high-priority browser flaw despite the need for user interaction.
What it is
Google Chrome before 93.0.4577.82 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger heap corruption, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it has been used in real attacks.
Impact
An attacker who gets the page rendered can corrupt the heap and potentially achieve code execution in the browser process context. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network by a victim loading a crafted HTML page; no privileges are required but user interaction (opening or viewing the page) is needed per the CVSS vector. No authentication is required.
Exploitation
Listed in CISA KEV with a 2021-11-17 remediation due date, and EPSS 30-day probability is 0.6319 (99.164 percentile), indicating high likelihood of exploitation activity. A public Packet Storm advisory describes Chrome JIT compiler type confusion, and no ransomware campaign use is documented.
What to do
- Update Chrome to 93.0.4577.82 or later, and apply the referenced Fedora package updates.
- Enforce automatic browser updates and verify version compliance across managed endpoints.
- Restrict or sandbox browsing of untrusted sites and block known malicious domains where feasible.
- Track CISA KEV remediation deadlines and confirm closure for internet-facing browsers.
Detection
- Monitor for Chrome renderer crashes or abnormal process terminations that may indicate heap corruption attempts.
- Hunt proxy and DNS logs for requests to known exploit-hosting or malformed HTML delivery domains.
- Alert on Chrome versions below 93.0.4577.82 reporting into inventory or EDR telemetry.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-30632 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Google Chromium V8 Out-of-Bounds Write Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-30632 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-30632), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.