RULE(RULE ID:333514)

Rule General Information
Release Date: 2021-05-08
Rule Name: Google Chrome versions before 89.0.4389.128 V8 XOR Typer Out-Of-Bounds Access RCE Vulnerability (CVE-2021-21220)
Severity:
CVE ID:
Rule Protection Details
Description: Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: http://packetstormsecurity.com/files/162437/Google-Chrome-XOR-Typer-Out-Of-Bounds-Access-Remote-Code-Execution.html
https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop.html
https://crbug.com/1196683
https://security.gentoo.org/glsa/202104-08
Solutions
Refer to the announcement or patch by the vendor: https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop.html