Skip to content
COOEY

EXPOSURES › CVE-2021-37976

CVE-2021-37976

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-37976 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

A remote attacker could extract sensitive data from Chromium browser processes via a crafted HTML page due to an unpatched memory disclosure flaw.

This information disclosure vulnerability in Chromium allows remote attackers to read sensitive data from browser memory, impacting any DIB organization relying on Chromium-based browsers like Chrome or Edge. The flaw was actively exploited in the wild and remains unpatched in older versions, representing a clear negligence failure in patch management. Organizations must enforce strict browser patching and consider alternative browsers for high-assurance environments.

Shame score — The vulnerability was actively exploited in the wild and remained unpatched for a significant period, demonstrating a failure in timely patch management and leaving systems exposed to data exfiltration.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Widespread acknowledgement of exploitation and inclusion in authoritative lists indicates significant negative impact.
cvefeed.io ↗ severe-fallout -0.90
Strongly negative; inclusion in CISA KEV catalog signifies active exploitation.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited."
cooey ↗ severe-fallout -0.80
Neutral reporting, but highlights broad impact.
"This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera."
www.cvefind.com ↗ severe-fallout -0.60
Lists Google as a vendor, contributing to negative perception.
"Vendors List All Vendor TOP 100 Vendors with CVE"
xposedornot.com ↗ severe-fallout +0.00
Neutral listing, no sentiment.
"Browse our complete data breach directory, built from the XposedOrNot database."
www.idtheftcenter.org ↗ severe-fallout +0.00
Neutral listing, no sentiment.
"Get information on the latest data compromises."
www.comparitech.com ↗ severe-fallout +0.00
Neutral listing, no sentiment.
"Recent ransomware attacks visualized on US map"
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized