4.3
CVSSv2

CVE-2021-37976

Published: 08/10/2021 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Inappropriate implementation in Memory in Google Chrome before 94.0.4606.71 allowed a remote malicious user to obtain potentially sensitive information from process memory via a crafted HTML page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

fedoraproject fedora 33

fedoraproject fedora 34

fedoraproject fedora 35

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure For the oldstable distribution (buster), security support for Chromium has been discontinued due to toolchain issues which no longer allow to build current Chromium releases on buster You can eit ...
An information leak security issue has been found in the core component of the Chromium browser engine before version 940460671 Google is aware that an exploit for this issue exists in the wild ...
The Stable channel has been updated to 940460671 for Windows, Mac and Linux which will roll out over the coming days/weeks Extended stable channel has also been updated to 940460671 for Windows and Mac which will roll out over the coming days/weeksA full list of changes in this build is available in the log Interested in switching release c ...

Recent Articles

Lawsuit claims hospital ransomware infection cost baby her life
The Register • Iain Thomson in San Francisco • 04 Oct 2021

Get our weekly newsletter Plus Russia arrests security boss, two Chrome flaws exploited

In Brief A hospital that continued to admit patients during a ransomware attack has been sued over claims that a baby died after doctors and nurses failed to spot there was a problem due to networks being shut down. Nicko Silar died after six months in intensive care after being born at Springhill Memorial Hospital with the umbilical cord wrapped around her neck, documents filed in the Alabama Circuit Court state [PDF]. The suit alleges that, because the hospital had shut down key networks, staf...

Predator spyware sold with Chrome, Android zero-day exploits to monitor targets
The Register • Jessica Lyons Hardcastle • 01 Jan 1970

Topics Security Off-Prem On-Prem Software Offbeat Vendor Voice Vendor Voice Resources Or so says Google after tracking 30+ vendors peddling surveillance malware

Spyware vendor Cytrox sold zero-day exploits to government-backed snoops who used them to deploy the firm's Predator spyware in at least three campaigns in 2021, according to Google's Threat Analysis Group (TAG). The Predator campaigns relied on four vulnerabilities in Chrome (CVE-2021-37973, CVE-2021-37976, CVE-2021-38000 and CVE-2021-38003) and one in Android (CVE-2021-1048) to infect devices with the surveillance-ware.  Based on CitizenLab's analysis of Predator spyware, Google's bug hun...