EXPOSURES › CVE-2021-37973
CVE-2021-37973
HIGH ⌖ ON CISA KEV · EXPLOITEDA use-after-free vulnerability in Google Chromium Portals allowed sandbox escapes via crafted HTML pages after the renderer process was compromised.
This use-after-free flaw in Chromium-based browsers (Chrome, Edge) enabled attackers to escape the browser sandbox once the renderer process was compromised, potentially leading to full system compromise. DIB organizations must ensure their Chromium-based browsers are patched immediately, as this vulnerability was actively exploited in the wild and highlights the risk of relying on widely deployed software with known, unpatched flaws.
Shame score — A known use-after-free vulnerability in a widely deployed browser was actively exploited in the wild, demonstrating severe negligence in patch management and reliance on software with critical, unpatched flaws.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects web browsers that utilize Chromium, including Google Chrome and Microsoft Edge.
"allows a remote attacker...to potentially perform a sandbox escape"
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |