LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-30632: Google Chromium V8 Out-of-Bounds Write Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-30632 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect…

CVE-2021-30632 is an out-of-bounds write vulnerability in the Google Chromium V8 JavaScript engine. A remote attacker can potentially trigger heap corruption by enticing a user to open a crafted HTML page. Because V8 is embedded in multiple Chromium-based browsers—including Google Chrome, Microsoft Edge, and Opera—the flaw can affect a wide range of desktop and enterprise browser deployments. Organizations should treat it as a high-priority browser risk and confirm exact impact and fixed builds against the vendor advisory.

How it works

The weakness is classified as CWE-122 (heap-based buffer overflow), an out-of-bounds write. In the V8 engine, memory management for JavaScript objects and intermediate representations can be abused so that a write operation exceeds the bounds of an allocated heap buffer. An attacker who can deliver a malicious HTML page (for example via a link, ad, or compromised site) may cause the browser process to corrupt heap memory. Successful exploitation can lead to arbitrary code execution inside the renderer or related process, depending on the browser’s sandboxing and other mitigations. Public detail on exact trigger conditions is limited; defenders should rely on the vendor advisory rather than assuming specific exploit primitives.

Am I affected? How to find it in your systems

Chromium V8 ships inside Google Chrome, Microsoft Edge, Opera, and other browsers or embedded WebView components that use the Chromium stack. It commonly appears on end-user workstations, VDI images, kiosks, and any application that bundles a Chromium-based renderer.

How to remediate

Patching is the primary remediation. Apply the vendor-supplied updates for every affected Chromium-based browser and embedded component as directed in the official advisories. CISA’s required action is simply to apply updates per vendor instructions.

If you can't patch immediately

When immediate patching is not possible, apply compensating controls to lower the likelihood and impact of successful exploitation:

If your data may have been exposed

Actively exploited browser vulnerabilities can lead to endpoint compromise and subsequent data theft. Known ransomware use of this specific CVE is not documented, but any successful heap-corruption exploit could still be leveraged for further access. If you suspect exposure, follow your incident-response process: isolate affected hosts, collect volatile evidence, and reset credentials that may have been present in the browser session. As a quick additional check, users can run a free exposure scan of their work email addresses against known breach data sets to see whether those addresses already appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGoogle · Chromium V8
WeaknessCWE-122
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities