CVE-2021-21148
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 5, 2026
18 articles
EPSS Score
Source: FIRST.org · 2026-05-24
24.87%
probability
This CVE has a 24.87% probability
of being exploited in the next 30 days.
0%
Top 96.2th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroHeap buffer overflow in V8
Attack Intelligence
Google Project Zero
Discovered
Jan. 24, 2021
Patched
Feb. 4, 2021
Reported by
Mattias Buelens
Root Cause Analysis
???
Google fixes second actively exploited Chrome zero-day this month
BleepingComputer
Mar 12, 2021
Google fixes Chrome zero-day actively exploited in the wild
BleepingComputer
Feb 04, 2021
Google pushes emergency Chrome update to fix zero-day used in attacks
BleepingComputer
Dec 13, 2021
Emergency Google Chrome update fixes zero-days used in attacks
BleepingComputer
Oct 28, 2021
Google patches 8th Chrome zero-day exploited in the wild this year
BleepingComputer
Jul 16, 2021
Google pushes emergency Chrome update to fix two zero-days
BleepingComputer
Sep 30, 2021
Google Chrome emergency update fixes zero-day exploited in attacks
BleepingComputer
Feb 14, 2022
Emergency Google Chrome update fixes zero-day exploited in the wild
BleepingComputer
Sep 24, 2021
Google patches 10th Chrome zero-day exploited in the wild this year
BleepingComputer
Sep 13, 2021
Google fixes seventh Chrome zero-day exploited in the wild this year
BleepingComputer
Jun 17, 2021
Google fixes sixth Chrome zero-day exploited in the wild this year
BleepingComputer
Jun 09, 2021
Qualys Response to CISA Alert: Binding Operational Directive 22-01
Qualys
Nov 09, 2021
Signal Intelligence
Confidence
95%
EPSS
24.87%
Mentions
18
Last Seen
Feb 14, 2022
CNA Information
Analyst Note
Auto-imported from Google Project Zero — confirmed zero-day by definition.
Triage Info
Decided atMar 05, 2026