ZeroHour

CVE-2021-37973

KEVmass1

Use-After-Free Sandbox Escape in Google Chrome/Chromium Portals

CISA: Google Chromium Portals Use-After-Free Vulnerability

CVSS 3.1
9.6 critical
EPSS
12%p96
Published
()
KEV added
AI analysis

CVE-2021-37973 is a use-after-free (CWE-416) in the Portals feature of Google Chrome prior to 94.0.4606.61. It is triggered via a crafted HTML page, and per the vendor description it allows a remote attacker who has already compromised the renderer process to potentially escape Chrome's sandbox; the CVSS vector confirms network reachability with required user interaction (UI:R). A successful exploit turns a renderer-level compromise into code execution outside the sandbox, with high impact to confidentiality, integrity, and availability (scope change, 9.6 critical). Anyone running Chrome or Chromium builds before 94.0.4606.61 is affected, including the chromium packages shipped by Fedora and Debian. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2021-11-03, Google patched it as one of two actively exploited Chrome zero-days (EPSS 11.6%, 96th percentile), no public PoC is known, and related reporting ties the era's actively exploited Chrome zero-days to mercenary spyware such as Intellexa/Cytrox's Predator.

What to do: Upgrade Google Chrome to 94.0.4606.61 or later (confirm the running version at chrome://version) and update the chromium packages on Fedora and Debian to their patched builds. Because the flaw is on the CISA KEV list, applying vendor updates is required for federal and critical-infrastructure environments; enable automatic browser updates and prioritize patching where users browse untrusted web content, since exploitation is typically delivered via crafted pages in a chain.

Affected
google chromeprior to 94.0.4606.61
fedora (chromium browser package)chromium builds prior to the upstream 94.0.4606.61 fix (specific package versions not stated in source data)
debian linux (chromium package)chromium builds prior to the upstream 94.0.4606.61 fix (specific package versions not stated in source data)
Estimated exposure
mass≈3 billion Chrome users/installs (Chrome holds roughly 65% global browser share), plus Chromium users on Fedora and Debian — Chrome is the world's dominant desktop browser with about two-thirds global market share — on the order of billions of users — and Fedora/Debian distribute Chromium to their large installed bases, so the vulnerable population plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium Portals
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlefedoraprojectdebian
Products
chrome, fedora, debian linux
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news