← back
CVE-2021-37976

CVE-2021-37976

CVSS 6.5 MEDIUMEPSS 19.9%● KEVCWE-862
In short

A flaw in Google Chrome's memory handling allowed attackers to access sensitive information from the browser's memory by crafting a malicious HTML page. This could expose passwords, tokens, or other private data.

Technical detail

CWE-862 (Improper Authorization/Missing Authorization). Remote attacker exploits improper memory access controls in Chrome's memory management subsystem via crafted HTML. Requires user to visit malicious page; impacts confidentiality of process memory contents. Fixed in Chrome 94.0.4606.71.

Summary generated and translated by AI from the official description.
Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Affected products
Google · Chrome

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →