CVE-2021-37975

HIGH KEV

Google Chrome < 94.0.4606.71 - Use-After-Free in V8 via Crafted HTML Page

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-37975 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021.

Description

Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Scores

CVSS v3 8.8
EPSS 0.6298
EPSS Percentile 98.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-09-24
InTheWild.io 2021-09-24
ENISA EUVD EUVD-2021-24448
CWE
CWE-416
Status published
Products (6)
debian/debian_linux 10.0
debian/debian_linux 11.0
fedoraproject/fedora 33
fedoraproject/fedora 34
fedoraproject/fedora 35
google/chrome < 94.0.4606.71
Published Oct 08, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026