PT-2021-5565 · Google+2 · Google Chrome+2

Published

2021-09-24

·

Updated

2024-06-15

·

CVE-2021-37956

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 94.0.4606.54
Description The issue is related to the use of memory after it has been freed, which can be exploited by a remote attacker to potentially execute code in the context of a privileged process. This can be achieved through a specially crafted HTML page. The exploitation may lead to heap corruption.
Recommendations For versions prior to 94.0.4606.54, update to version 94.0.4606.54 or later to resolve the issue. As a temporary workaround, consider restricting access to offline mode in Google Chrome on Android until the update is applied.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2909
ALT-PU-2021-2987
ALT-PU-2021-2988
ALT-PU-2021-3044
ALT-PU-2021-3050
ALT-PU-2021-3436
ALT-PU-2021-3603
BDU:2021-06421
CVE-2021-37956
DSA-5046-1
OPENSUSE-SU-2021:1339-1
OPENSUSE-SU-2021:1350-1
OPENSUSE-SU-2021_1350-1
OPENSUSE-SU-2024:11555-1
OPENSUSE-SU-2024:12948-1

Affected Products

Alt Linux
Google Chrome
Suse