CVE-2021-21148

HIGH KEV

Google Chrome <88.0.4324.150 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-21148 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021. EIP tracks 1 public exploit from researchers including Grayhaxor.

AI-analyzed exploit summary The repository contains only a minimal README with no technical details, exploit code, or meaningful analysis. It appears to be a placeholder or lure with no substantive content.

Description

Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Exploits (1)

nomisec SUSPICIOUS 2 stars
by Grayhaxor · poc
https://github.com/Grayhaxor/CVE-2021-21148

The repository contains only a minimal README with no technical details, exploit code, or meaningful analysis. It appears to be a placeholder or lure with no substantive content.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.1981
EPSS Percentile 97.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-01-24
InTheWild.io 2021-01-24
ENISA EUVD EUVD-2021-8539
CWE
CWE-787
Status published
Products (4)
debian/debian_linux 10.0
fedoraproject/fedora 32
fedoraproject/fedora 33
google/chrome < 88.0.4324.150
Published Feb 09, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026