CVE-2021-37976
MEDIUM KEVGoogle Chrome < 94.0.4606.71 - Missing Authorization
Title source: ruleDescription
Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
References (7)
Scores
CVSS v3
6.5
EPSS
0.0768
EPSS Percentile
91.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Details
CISA KEV
2021-11-03
VulnCheck KEV
2021-09-21
InTheWild.io
2021-09-21
ENISA EUVD
EUVD-2021-24449
CWE
CWE-862
Status
published
Products (6)
debian/debian_linux
10.0
debian/debian_linux
11.0
fedoraproject/fedora
33
fedoraproject/fedora
34
fedoraproject/fedora
35
google/chrome
< 94.0.4606.71
Published
Oct 08, 2021
KEV Added
Nov 03, 2021
Tracked Since
Feb 18, 2026