Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Nov 17, 2021

CVE-2021-38003

High
EPSS 71.4%CISA KEV
Google/Chromium V8

Description

Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EPSS — Exploit Probability

71.4%

Higher than 98.7% of all CVEs

Required Action

https://nvd.nist.gov/vuln/detail/CVE-2021-38003

Risk Assessment

HIGH
In CISA KEV
High EPSS

Details

Severity
High
EPSS
71.4%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Nov 3, 2021

Added to KEV

Nov 3, 2021

Remediation Due

Nov 17, 2021

Affected Product

Google

Chromium V8

View all Google CVEs