ZeroHour

CVE-2021-37976

KEV PoC mass1

Information Disclosure in Google Chrome/Chromium Memory Implementation (CVE-2021-37976)

CISA: Google Chromium Information Disclosure Vulnerability

CVSS 3.1
6.5 medium
EPSS
20%p97
Published
()
KEV added
AI analysis

A memory implementation flaw (inappropriate implementation, tracked as CWE-862) in Google Chrome and Chromium prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from browser process memory. The flaw is reachable over the network with low complexity: an attacker needs no privileges but must convince a user (user interaction required) to load a crafted HTML page, e.g. by visiting an attacker-controlled website. A successful attacker gains read access to potentially sensitive data from the affected process's memory, with no direct impact on integrity or availability per the CVSS score. All Chrome/Chromium users running builds older than 94.0.4606.71 are affected, including Chromium as packaged and distributed by Fedora and Debian. The vulnerability is confirmed exploited in the wild: it was added to CISA's KEV on 2021-11-03 (ransomware use unknown), EPSS puts 30-day exploitation probability at 19.7% (97th percentile), and reporting around the Intellexa leaks ties the Chrome zero-day fixes of this period to Cytrox/Predator mercenary spyware operations.

What to do: Upgrade Google Chrome/Chromium to 94.0.4606.71 or later immediately, per the CISA KEV required action; on Fedora and Debian, apply the distribution's Chromium security updates. Audit endpoints for browser versions below 94.0.4606.71 and prioritize internet-facing or high-value users given known in-the-wild exploitation and links to Predator spyware campaigns. No reliable mitigation short of updating exists; restricting browsing with unpatched builds reduces exposure.

Affected
google chromeprior to 94.0.4606.71
google chromiumprior to 94.0.4606.71 (CISA lists Google Chromium as affected)
fedoraproject fedora
debian linux
Estimated exposure
massbillions of users (Chrome is the dominant desktop browser at roughly 60-65% market share; the vulnerable population before the October 2021 fix was effectively… — Estimated from Chrome's multi-billion global install base and ~60-65% desktop browser market share, with Fedora/Debian Chromium users adding a comparatively small share.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlefedoraprojectdebian
Products
chrome, fedora, debian linux
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news