CVE-2021-38003Active Exploitation(debian / chrome)

HIGHCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch debian chrome systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

6.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2021-11-17. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-755

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • debian_linux
  • fedora

Threat summary

  • Active exploitation appears in 6 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days

What's happening

  • Active exploitation reported across 6 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Peaked 2d ago at 3 mentions (2026-09-11); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
chromedebian_linuxfedora

3 versions affected across 3 products

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-04-13: 1Mentions · 2026-09-11: 3Mentions · 2026-09-13: 1Mentions · 2026-09-14: 1Exploit Tool / Code · 2026-09-11: 1Active Exploitation · 2026-04-13: 1Active Exploitation · 2026-09-11: 3Active Exploitation · 2026-09-13: 1Active Exploitation · 2026-09-14: 1Patch / Workaround · 2026-09-11: 1Patch / Workaround · 2026-09-13: 1Patch / Workaround · 2026-09-14: 1Technical Details · 2026-04-13: 1Technical Details · 2026-09-11: 2Technical Details · 2026-09-13: 104-1309-1109-1309-14
Signal classification1 categories
Active Exploitation
6100.0%
Referenced assets34 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-131
Active Exploitation1
2026-09-113
Active Exploitation3
2026-09-131
Active Exploitation1
2026-09-141
Active Exploitation1
Full discourse6 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ A crafted Sogou Input Method link led to GRAYRABBIT malware. China-linked UNC3569 abused Sogou’s sgbiz: handler to open a malicious page in its built-in Chromium 80 browser, then exploited CVE-2021-38003 to run code with the logged-in user’s privileges. Read: https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html

    Post summary

    China-linked UNC3569 used a malicious Sogou Input Method link to deliver GRAYRABBIT malware by exploiting CVE-2021-38003 in the built-in Chromium 80 browser, demonstrating active exploitation of the vulnerability.

    59048834.7K
    2.4M followersView on X
  • Dark Web Intelligence@DailyDarkWeb
    Active Exploitation

    🇨🇳🚨 CHINA-LINKED HACKERS EXPLOITED CRITICAL SOGOU INPUT METHOD FLAW TO DEPLOY GRAYRABBIT BACKDOOR Gen Threat Labs has disclosed active exploitation of CVE-2026-51990, a critical vulnerability affecting Tencent's Sogou Input Method for Windows. The vulnerability was discovered while researchers were investigating a real-world intrusion involving UNC3569 — a China-linked threat actor associated with espionage activity. The attack required only ONE CLICK on a specially crafted sgbiz: link. Attack chain: Malicious link → Sogou's sgbiz: protocol handler → Attacker-controlled arguments → Embedded Chromium browser → Browser exploitation → Remote code execution → GRAYRABBIT backdoor The situation was made considerably worse by Sogou's embedded browser. Researchers found it was based on Chromium 80 — roughly six years old — with: * Chromium sandbox disabled * Same-origin protections disabled * Years of known browser vulnerabilities potentially exposed In the observed attack, UNC3569 used CVE-2021-38003, an older V8 vulnerability, as part of the exploitation chain. Successful exploitation ultimately deployed GRAYRABBIT. The backdoor provides attackers with: * Remote command execution * File upload/download capabilities * Additional payload deployment * Persistent remote access Gen says UNC3569 has historically targeted government, education, technology and financial organizations, primarily across East and Southeast Asia. ⚠️ IMPORTANT: This vulnerability HAS been exploited in the wild. However, it is no longer an unpatched zero-day. Gen reported CVE-2026-51990 to Tencent on April 9, 2026. Tencent completed the fix 12 days later and distributed Sogou Input Method version 16.3.0.3498 through automatic updates. ⚠️ Analyst Note: The most interesting part of this attack isn't simply another RCE. It's the attack surface created when ordinary desktop applications quietly embed entire browser engines. An input method shouldn't intuitively look like an internet-facing attack surface. But here: Custom URI handler + Embedded browser + Outdated Chromium + Disabled sandbox + Disabled web-security protections turned a language input application into an initial-access vector for an espionage operation. Organizations with Sogou Input Method installed should verify that endpoints are running the patched version and hunt for historical indicators of GRAYRABBIT activity. Original research — Gen Threat Labs: https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou #DDW #UNC3569 #Sogou #GRAYRABBIT #CyberSecurity

    Post summary

    The text reports active in-the-wild exploitation of CVE-2026-51990 in Tencent's Sogou Input Method by UNC3569, leading to RCE and GRAYRABBIT deployment. It also notes that the vulnerability has been patched in Sogou Input Method version 16.3.0.3498.

    110767.3K
    207.6K followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    【リンク集:週末のセキュリティ関連ニュース/記事】 <脆弱性> ・Check PointがVPNの重大な脆弱性を修正(CVE-2026-85102、CVE-2026-85103) https://www.securityweek.com/check-point-patches-critical-vpn-vulnerabilities/ ・GitLab、最大深刻度のパストラバーサル脆弱性にパッチ適用するようユーザーに促す(CVE-2026-85706) https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/ ・GitLabの脆弱性が公表翌日に悪用される(CVE-2026-85706) https://www.securityweek.com/gitlab-vulnerability-exploited-one-day-after-disclosure/ ・米CISAがJFrog Artifactory、ScreenConnect、MikroTik RouterOSなどの欠陥5件をKEVカタログに追加(CVE-2026-42016、CVE-2026-42018他) https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html ・Check Point VPNの重大な脆弱性は悪用の危険大、蘭NCSCが注意を呼びかけ(CVE-2026-85102、CVE-2026-85103) https://www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent/ <マルウェア・その他脅威> ・ロシアのハッカー、マルウェアの検知回避目的でClaudeを使用 アンソロピックが発表 https://www.securityweek.com/anthropic-says-russian-hackers-used-claude-ai-to-automate-malware-evasion/ ・中国関連グループUNC3569がSogou Input Methodの欠陥悪用し、GRAYRABBITバックドアを展開(CVE-2021-38003) https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html ・GuardBreaker:コードのコメントを使い、AI活用したマルウェア分析を妨害 https://www.welivesecurity.com/en/business-security/guardbreaker-derailing-ai-assisted-malware-analysis-code-comment/ ・PCやMacに感染するClickFix攻撃が急速に拡大https://arstechnica.com/security/2026/09/clickfix-attacks-infecting-pcs-and-macs-are-going-viral/ ・パスキー関連のフィッシング攻撃でMicrosoft 365のデータが盗まれる https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/ <データ侵害/サイバー犯罪> ・Revolut、政府機関のメールアドレスを悪用した詐欺師に顧客データを提供 https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/ ・フロリダ州交通安全局、盗まれた警察アカウント経由でDMVデータベースの侵害被害を確認 https://www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/ ・VPNサービスSurfsharkのシステムが攻撃受ける https://www.securityweek.com/surfshark-systems-targeted-by-hackers/ ・Trezorのユーザー34万7,000人がフィッシングメールを受信 Brevoでインシデント発生後 https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/ ・英自治体が受けた攻撃、SonicWallの欠陥悪用した大規模キャンペーンと関連か(CVE-2026-15409) https://securityaffairs.com/198864/hacking/uk-council-attack-linked-to-mass-exploitation-of-sonicwall-flaw.html ・JFrog Artifactoryの欠陥2件を連鎖して悪用する攻撃発生 管理者権限の取得後にバックドアが仕込まれる(CVE-2026-42018、CVE-2026-42016) https://thehackernews.com/2026/09/attackers-chain-jfrog-artifactory-flaws.html <AI関連> ・AI悪用が新たなフェーズへ:サイバー犯罪から監視、プロパガンダ、兵器利用まで ー アンソロピックが報告 https://securityaffairs.com/198905/ai/anthropic-ai-misuse-is-entering-a-new-phase-from-cybercrime-to-surveillance-propaganda-and-weapons.html ・アンソロピックCEO、AI業界は安全対策が追いつくための時間を確保すべきと発言 https://www.securityweek.com/anthropic-ceo-dario-amodei-says-ai-industry-needs-to-give-safety-measures-time-to-catch-up/ ・中国拠点のAI研究所7か所でClaude使った大規模な蒸留攻撃を実施 アンソロピックが発表 https://thehackernews.com/2026/09/anthropic-says-seven-china-based-ai.html ・AIは燃料やコストのために動物の命を犠牲にする傾向 https://www.theregister.com/ai-and-ml/2026/09/11/ai-more-likely-to-kill-animals-if-it-saves-fuel-or-money/5295993 ・AstraがAI使った攻撃のレベルを引き上げ 防御側にとって意味するものとは https://arcticwolf.com/resources/blog/astra-raised-the-bar-for-ai-enabled-attacks/ ・OpenAIのAIエージェントがRubyGemsを攻撃するキャンペーンに関与か RubyDocサーバーでRCEを実行 https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html ・Claudeユーザーが生物兵器の研究目的で安全対策の抜け道探る アンソロピックが複数の試みを阻止 https://arstechnica.com/ai/2026/09/claude-users-found-ways-around-safeguards-for-bioweapons-research/ <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・Contiランサムウェア開発者のウクライナ人、米裁判所で拘禁4年の実刑判決 https://www.securityweek.com/ukrainian-conti-ransomware-developer-sentenced-to-4-years-in-us-prison/ ・AT&Tの店舗従業員、SIMスワップで収入得たとして拘禁16か月の実刑判決 https://www.theregister.com/cyber-crime/2026/09/11/att-store-worker-gets-16-months-inside-for-sim-swap-side-hustle/5295898 <プライバシー> ・2,300万人が利用する人気旅行アプリ、軍人含むユーザーの行動が監視可能に https://cybernews.com/security/polarsteps-travel-app-exposes-users-soldiers/ <リサーチ/攻撃手法/TTP> ・「スキルポイズニング攻撃」でAIエージェントがマルウェアドロッパーに変貌 中国CVERCが警告 https://ministryofcyberaffairs.com/news/skill-poisioning-turning-ai-agents-into-malware-droppers-warns-china-s-national-cert-66b8bba4-9ffd-4583-a6c7-122e8149e0e8 ・Beltdown2:Cursor CLIサンドボックスに脱出経路が存在 https://www.accomplish.ai/blog/beltdown2-escaping-the-cursor-cli-sandbox/ <その他> ・FBIのサイバー部門責任者、同局初の非機密サイバー戦略を発表 https://federalnewsnetwork.com/cybersecurity/2026/09/fbi-cyber-leader-details-bureaus-first-unclassified-cyber-strategy/ ・EUサイバーレジリエンス法により、24時間以内の脆弱性報告が義務化 https://www.theregister.com/security/2026/09/11/eus-cyber-resilience-act-starts-the-24-hour-vulnerability-clock/5295821

    Post summary

    The text reports multiple CVEs, highlighting active exploitation (e.g., GitLab CVE-2026-85706, CISA KEV additions) and mitigation steps (patches by Check Point and GitLab) without detailing exploit tools or technical specifics.

    000301.2K
    1.3K followersView on X
  • SecureChap@SecureChap
    Active Exploitation

    UNC3569 used the sgbiz: link handler in Sogou Input Method to invoke SGMyInput.exe with an attacker-supplied URL. The handler launched the bundled Chromium 80 skin-store browser with sandbox and same-origin policy disabled. CVE-2021-38003 in V8 JSON.stringify provided the initial foothold. The page at noht1ng[.]top then dropped the GRAYRABBIT loader. 7z.dll (29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63) wrote to C:\Users\Public\Documents. It waited for at least 50 running processes before decrypting core.dll (d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a) from an NTFS alternate data stream, then deleted itself. GRAYRABBIT connected over plain TCP+RC4 to mail.uaiubifas[.]top:443. Tencent issued CVE-2026-51990 in version 16.3.0.3498 on 21 April 2026, restricting the handler to HTTPS and four allowed host suffixes. The same build still ships Chromium 80 with sandbox and web-security flags disabled.

    Post summary

    UNC3569 has actively exploited CVE‑2021‑38003 via the sgbiz handler in Sogou Input Method, dropping a GRAYRABBIT loader with detailed DLL and network indicators. A new CVE‑2026‑51990 is introduced to restrict future handler usage, but no patch for the original CVE is mentioned.

    0000075
    172 followersView on X
  • The Daily Tech Feed@dailytechonx
    Active Exploitation

    Massive risk: criminals tied to UNC3569 used a flaw in Sogou Input Method’s custom link handler and its outdated Chromium 80 engine to install the GRAYRABBIT backdoor. The exploit involved sgbiz: links, disabled sandbox & same-origin policy, plus CVE-2021-38003—patched only in version 16.3.0.3498. If you use Sogou, update ASAP, check for network connections to http://mail.uaiubifas.top, and verify your version to avoid compromise. #GRAYRABBIT #UNC3569 #Sogou #Cybersecurity #Vulnerability #China https://thedailytechfeed.com/chinese-apt-unc3569-used-sogou-flaw-to-drop-grayrabbit-backdoor/

    Post summary

    Criminals tied to UNC3569 exploited a CVE‑2021‑38003 flaw in Sogou Input Method, using custom link handling to drop the GRAYRABBIT backdoor, while urging users to update to a patched version to mitigate the risk.

    0000072
    723 followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2021-38003 Exploit in the wild confirmed for CVE-2021-38003 (CVSS null). Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value ... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The tweet reports confirmed wild exploitation of CVE-2021-38003 on the Chromium V8 Engine, describing a JSON.stringify bug, but offers no patch, PoC, or exploit code.

    0000065
    5.6K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux10.0--
OSdebiandebian_linux11.0--
OSfedoraprojectfedora34--
Appgooglechrome---

Explore more