← Back to browse · API

CVE-2021-38003

Severity
HIGH
CVSS
8.8
EPSS
0.38573
Risk score
73.7
CISA KEV
Yes
PoC
Yes
Published
2021-11-03
Modified
2021-11-03
First seen
2026-08-07
Aliases
EUVD-2021-24476, GHSA-4XX3-XG55-3WR5
Products
Google:Chrome unspecified <95.0.4638.69, Google:Chromium V8
Sources
euvd EUVD-2021-24476
cisa.gov CVE-2021-38003
packetstorm 8188b67aa0618559931665ed|CVE-2021-38003

Description

Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

References