PT-2021-4291 · Google+3 · Google Chrome+3

Clément Lecigne

·

Published

2021-09-30

·

Updated

2025-12-04

·

CVE-2021-37976

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 94.0.4606.71
Description The issue is related to the inappropriate implementation in memory, allowing a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This could enable an unauthorized party to access protected information.
Recommendations For versions prior to 94.0.4606.71, update to version 94.0.4606.71 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information when using affected versions of Google Chrome until a patch is applied.

Exploit

Fix

Information Disclosure

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2962
ALT-PU-2021-2987
ALT-PU-2021-2988
ALT-PU-2021-3044
ALT-PU-2021-3050
ALT-PU-2021-3436
ALT-PU-2021-3603
BDU:2021-04900
CVE-2021-37976
DSA-5046-1
OPENSUSE-SU-2021:1339-1
OPENSUSE-SU-2021:1350-1
OPENSUSE-SU-2021:1358-1
OPENSUSE-SU-2021:1433-1
OPENSUSE-SU-2021:1434-1
OPENSUSE-SU-2021_1350-1
OPENSUSE-SU-2021_1358-1
OPENSUSE-SU-2021_1433-1
OPENSUSE-SU-2021_1434-1
OPENSUSE-SU-2022:0110-1
OPENSUSE-SU-2022_0110-1
OPENSUSE-SU-2024:11555-1
OPENSUSE-SU-2024:12948-1

Affected Products

Alt Linux
Astra Linux
Google Chrome
Suse