CVE-2021-37973
CRITICAL KEVGoogle Chrome < 94.0.4606.61 - Use After Free
Title source: ruleDescription
Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
References (6)
Scores
CVSS v3
9.6
EPSS
0.0650
EPSS Percentile
91.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Details
CISA KEV
2021-11-03
VulnCheck KEV
2021-09-21
InTheWild.io
2021-09-21
ENISA EUVD
EUVD-2021-24446
CWE
CWE-416
Status
published
Products (5)
debian/debian_linux
10.0
debian/debian_linux
11.0
fedoraproject/fedora
33
fedoraproject/fedora
35
google/chrome
< 94.0.4606.61
Published
Oct 08, 2021
KEV Added
Nov 03, 2021
Tracked Since
Feb 18, 2026