MEDIUM

CVE-2021-37976

Google Chrome 2021-10-08 CVSS v3.1
CVSS
6.5
KEV

Description

Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

Summary dbcve.org

Google Chrome versions prior to 94.0.4606.71 contain an inappropriate implementation in memory handling that allows a remote attacker to read process memory contents through a maliciously crafted HTML page, potentially exposing sensitive information from the browser process.

Mitigation

Update Google Chrome to version 94.0.4606.71 or later to apply the memory safety patch. In enterprise environments, ensure automated browser update policies are enforced.

Proof of Concept

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

19.9%
Probability of exploitation in next 30 days
97.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE