CVE-2021-37976KEV · OVERDUE

Google Chromium Information Disclosure Vulnerability

Medium · published October 8, 2021

Patch now

The score understates this — it's already being exploited

CVSS calls it medium at 6.5. It is confirmed in active exploitation. It sits in the 97.2th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
6.5
EPSS
20%
Percentile
97.2
In the wild
Confirmed
What it is

⚠️ A clever HTML page can steal data from Google Chrome’s memory without breaking a sweat! Just like leaving a snack on the table can lure a hungry raccoon, a remote attacker can access sensitive information if your Chrome version is out of date. 😱 Think of it like this: if your computer's memory is a messy kitchen, this vulnerability lets an intruder peek through the window and grab leftovers without ever entering the house. It's surprisingly easy for them to snag what they want if you're not careful! An attacker exploiting this vulnerability could potentially harvest sensitive information from your browser's memory — think passwords, cookies, or personal data that you believed were well-protected. It’s a bit like leaving the door ajar while cooking; you never know who might take a quick peek inside!

Put simply

Think of it like this: if your computer's memory is a messy kitchen, this vulnerability lets an intruder peek through the window and grab leftovers without ever entering the house. It's surprisingly easy for them to snag what they want if you're not careful! CVE-2021-37976 is an inappropriate implementation in the memory management of Google Chrome that allows remote attackers to read sensitive process memory through a specially crafted HTML page.

What to do

An attacker exploiting this vulnerability could potentially harvest sensitive information from your browser's memory — think passwords, cookies, or personal data that you believed were well-protected. It’s a bit like leaving the door ajar while cooking; you never know who might take a quick peek inside! Update Google Chrome to version 94.0.4606.71 or later immediately to patch this vulnerability. Regularly check for updates and consider enabling automatic updates to avoid future surprises. Stay vigilant and review your browsing habits! You’ve got this! Follow these steps, and you’ll be back on track, making the internet a safer place for everyone. 🛡️

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.19748 · 97.2th percentile
Published
2021-10-08T21:50Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 08 OCT 21:50Z
    Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from…
    cvelistv5