Vulnerability record · CVE-2021-37975 · published 8 October 2021
CVE-2021-37975: Google Chrome V8 use-after-free allows heap corruption
Google · Chrome
Google Chrome before 94.0.4606.71 contains a use-after-free flaw in the V8 JavaScript engine. A crafted HTML page can trigger heap corruption, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.
Description
Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with a high EPSS score and high CVSS impact, though exploitation requires the victim to open a crafted page.
What it is
Google Chrome before 94.0.4606.71 contains a use-after-free flaw in the V8 JavaScript engine. A crafted HTML page can trigger heap corruption, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.
Impact
An attacker who gets the page rendered can potentially corrupt the heap and execute code in the browser process, gaining the user's privileges. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network by a victim loading a crafted HTML page; no authentication is required, but user interaction (opening the page) is needed per the CVSS vector (AV:N/AC:L/PR:N/UI:R).
Exploitation
CISA added it to the KEV catalog on 2021-11-03 with a 2021-11-17 remediation due date, and EPSS gives a 30-day probability of 0.34887 (98th percentile). No ransomware campaign use is documented.
What to do
- Update Chrome to 94.0.4606.71 or later, and apply the corresponding Fedora and Debian updates.
- Track the CISA KEV due date and confirm all affected endpoints are patched.
- Where immediate patching is not possible, restrict browsing to trusted sites and enforce script controls.
- Verify browser version compliance across the fleet through your software inventory.
Detection
- Monitor for Chrome processes crashing or exhibiting heap corruption indicators on endpoints.
- Hunt for users visiting newly registered or low-reputation domains that serve exploit pages.
- Review proxy and DNS logs for known exploit-hosting infrastructure tied to this CVE.
- Alert on Chrome versions below 94.0.4606.71 reported by endpoint inventory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-37975 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Google Chromium V8 Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-37975 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-37975), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.