However, beyond classifying the flaw as a heap-buffer overflow, Google did not specify the potential impact of this vulnerability. What is a Heap-Buffer Overflow Security Flaw?Ī heap-buffer overflow flaw as its name suggests, is a type of buffer-overflow error. This is a class of vulnerability where the region of a process’ memory used to store dynamic variables (the heap) can be overwhelmed. If a buffer-overflow occurs, it typically causes the affected program to behave incorrectly, according to researchers with Imperva – causing memory access errors and crashes - and opening the door to remote code execution. “Google is aware of reports that an exploit for CVE-2021-21148 exists in the wild,” according to Google’s Thursday security update. The flaw ( CVE-2021-21148) stems from a heap-buffer overflow, said Google. This update will roll out over the coming days and weeks, said Google.
Google is warning of a zero-day vulnerability in its V8 open-source web engine that’s being actively exploited by attackers.Ī patch has been issued in version 88 of Google’s Chrome browser - specifically, version.