Skip to content
COOEY

EXPOSURES › CVE-2021-37973

CVE-2021-37973

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-37973 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

A use-after-free vulnerability in Google Chromium Portals allowed sandbox escapes via crafted HTML pages after the renderer process was compromised.

This use-after-free flaw in Chromium-based browsers (Chrome, Edge) enabled attackers to escape the browser sandbox once the renderer process was compromised, potentially leading to full system compromise. DIB organizations must ensure their Chromium-based browsers are patched immediately, as this vulnerability was actively exploited in the wild and highlights the risk of relying on widely deployed software with known, unpatched flaws.

Shame score — A known use-after-free vulnerability in a widely deployed browser was actively exploited in the wild, demonstrating severe negligence in patch management and reliance on software with critical, unpatched flaws.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects web browsers that utilize Chromium, including Google Chrome and Microsoft Edge.

SENTIMENT · TRUSTED SOURCES
synthesis negative -0.60
Significant security flaw with potential for serious exploitation.
cooey ↗ negative -0.70
Identifies a serious vulnerability impacting multiple browsers.
"allows a remote attacker...to potentially perform a sandbox escape"
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized