CVE-2021-37973

CVE Published 2021-10-08
Related CWE(s) CWE-416: Use After Free
Related Vendor(s) fedoraproject, debian, google
Related Product(s) fedora, chrome, debian_linux
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 9.6 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

References