EXPOSURES › CVE-2021-37976
CVE-2021-37976
HIGH ⌖ ON CISA KEV · EXPLOITEDA remote attacker could extract sensitive data from Chromium browser processes via a crafted HTML page due to an unpatched memory disclosure flaw.
This information disclosure vulnerability in Chromium allows remote attackers to read sensitive data from browser memory, impacting any DIB organization relying on Chromium-based browsers like Chrome or Edge. The flaw was actively exploited in the wild and remains unpatched in older versions, representing a clear negligence failure in patch management. Organizations must enforce strict browser patching and consider alternative browsers for high-assurance environments.
Shame score — The vulnerability was actively exploited in the wild and remained unpatched for a significant period, demonstrating a failure in timely patch management and leaving systems exposed to data exfiltration.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited."
"This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera."
"Vendors List All Vendor TOP 100 Vendors with CVE"
"Browse our complete data breach directory, built from the XposedOrNot database."
"Get information on the latest data compromises."
"Recent ransomware attacks visualized on US map"
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |