MEDIUM
CVE-2021-37976
CVSS
6.5
KEV
Description
Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Summary dbcve.org
Google Chrome versions prior to 94.0.4606.71 contain an inappropriate implementation in memory handling that allows a remote attacker to read process memory contents through a maliciously crafted HTML page, potentially exposing sensitive information from the browser process.
Mitigation
Update Google Chrome to version 94.0.4606.71 or later to apply the memory safety patch. In enterprise environments, ensure automated browser update policies are enforced.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
19.9%
Probability of exploitation in next 30 days
97.3th percentile
References
https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_30.html
Release Notes
https://crbug.com/1251787
Exploit, Issue Tracking, Vendor Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D63JZ3ROXCUHP4CFWDHCPZNTGET7T34R/
Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRFXUDH46PFVE75VQVWY6PYY5DK3S2XT/
Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RNARCF5HEZK7GJXZRN5TQ45AQDCRM2WO/
Release Notes
https://www.debian.org/security/2022/dsa-5046
Mailing List, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-37976
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.