Executive brief
An inappropriate implementation in the core memory component of Google Chromium allows a remote attacker to obtain sensitive information from process memory. The vulnerability is triggered when a user visits a specially crafted HTML page.
Affected products
- Google Chrome prior to 94.0.4606.71
- Microsoft Edge
- Opera Opera
Timeline
- 2021-09-30: patched: Google released Chrome version 94.0.4606.71 to address this issue.
- 2021-11-03: disclosed: Vulnerability published and added to CISA KEV catalog.
- 2021-11-03: kev added
- 2021-11-03: exploited: Reported as exploited in the wild.