Junglewise Threat Intelligence

CVE-2021-37976: Google Chromium Information Disclosure Vulnerability

CVE-2021-37976 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2021-11-03

Technologies: Google Chrome, Google Chromium, Microsoft Edge. Vendors: Opera, Google, Microsoft.

Executive brief

An inappropriate implementation in the core memory component of Google Chromium allows a remote attacker to obtain sensitive information from process memory. The vulnerability is triggered when a user visits a specially crafted HTML page.

Affected products

  • Google Chrome prior to 94.0.4606.71
  • Microsoft Edge
  • Opera Opera

Timeline

  • 2021-09-30: patched: Google released Chrome version 94.0.4606.71 to address this issue.
  • 2021-11-03: disclosed: Vulnerability published and added to CISA KEV catalog.
  • 2021-11-03: kev added
  • 2021-11-03: exploited: Reported as exploited in the wild.

Related threats