Record summary

CVE-2021-37976 has a selected CVSS score of 6.5 (medium). CISA lists CVE-2021-37976 in KEV.

Description

Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Nov 3, 2021 · CISA
VulnCheck KEV
Listed · Sep 21, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListBefore 94.0.4606.71affected
CISAVersion data not supplied

References

11