Junglewise Threat Intelligence

CVE-2021-37973: Google Chromium Portals Use-After-Free Vulnerability

CVE-2021-37973 · Severity: critical · CVSS 9.6 · Exploited in the wild · Published 2021-11-03

Technologies: Google Chrome, Microsoft Edge, Google Chromium. Vendors: Google, Microsoft.

Executive brief

A use-after-free vulnerability exists in the Portals component of Google Chromium. A remote attacker who has already compromised the renderer process can exploit this flaw via a crafted HTML page to achieve a sandbox escape.

Affected products

  • Google Chrome prior to 94.0.4606.61
  • Microsoft Edge
  • Google Chromium

Timeline

  • 2021-09-24: patched: Stable channel update for desktop 94.0.4606.61 released.
  • 2021-11-03: disclosed: Vulnerability published and added to CISA KEV catalog.
  • 2021-11-03: kev added
  • 2021-11-03: exploited: Reported as exploited in the wild.